{"id":"CVE-2026-63495","aliases":["GHSA-qx89-wf2v-vgmx"],"url":"https://o3.security/vulnerability/CVE-2026-63495","summary":"Libevent: Unbounded memory accumulation in WebSocket server via fragmented frames","details":"Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frames in evws->incomplete_frames without enforcing a total message-size limit. An unauthenticated remote client can repeatedly send fragmented WebSocket frames below WS_MAX_RECV_FRAME_SZ with FIN=0, causing the evbuffer to grow without bound until the process or host exhausts memory. This issue is fixed in version 2.2.2-alpha.","published":"2026-08-20T17:49:16.790Z","modified":"2026-08-22T03:49:39.715330206Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/libevent/libevent/commit/291c4d1cd75695e898030ebd5c4ddf26c094077b","label":"libevent/libevent@291c4d1"},"references":[{"type":"WEB","url":"https://github.com/libevent/libevent/releases/tag/release-2.2.2-alpha"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63495.json"},{"type":"ADVISORY","url":"https://github.com/libevent/libevent/security/advisories/GHSA-qx89-wf2v-vgmx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63495"},{"type":"FIX","url":"https://github.com/libevent/libevent/commit/291c4d1cd75695e898030ebd5c4ddf26c094077b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-22T03:49:39.715330206Z"}}