Skip to main content

CVE-2026-63380

CVE Details​

Visit the official vulnerability details page for CVE-2026-63380 to learn more.

Initial Publication​

08/20/2026

Last Update​

08/25/2026

Third Party Dependency​

libevent

NIST CVE Summary​

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null http_server and unconditionally calls TAILQ_REMOVE even though the session was never inserted into http_server->ws_sessions. A local caller able to induce this allocation or locking failure can crash the process. This issue is fixed in version 2.2.2-alpha.

CVE Severity​

5.7

Our Official Summary​

Investigation is ongoing to determine how this vulnerability affects our products.

Status​

Received

Affected Products & Versions​

VersionPaletteAIPaletteAI VerteX
1.4.0⚠️ Impacted⚠️ Impacted
1.3.2⚠️ Impacted⚠️ Impacted
1.2.2⚠️ Impacted⚠️ Impacted

Revision History​

No revisions available.