Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4289-1 | python-eventlet security update |
EUVD |
EUVD-2025-26392 | Eventlet affected by HTTP request smuggling in unparsed trailers |
Github GHSA |
GHSA-hw6f-rjfj-j7j7 | Eventlet affected by HTTP request smuggling in unparsed trailers |
Ubuntu USN |
USN-7772-1 | Eventlet vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 04 Nov 2025 04:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 25 Sep 2025 03:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:eventlet:eventlet:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 02 Sep 2025 23:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 31 Aug 2025 17:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eventlet
Eventlet eventlet |
|
| Vendors & Products |
Eventlet
Eventlet eventlet |
Sat, 30 Aug 2025 09:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Sat, 30 Aug 2025 06:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients. | |
| Title | Eventlet affected by HTTP request smuggling in unparsed trailers | |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T18:13:48.690Z
Reserved: 2025-08-22T14:30:32.223Z
Link: CVE-2025-58068
Updated: 2025-09-02T13:50:18.375Z
Status : Modified
Published: 2025-08-29T22:15:32.327
Modified: 2025-11-03T19:16:13.340
Link: CVE-2025-58068
OpenCVE Enrichment
Updated: 2025-08-31T17:41:34Z
Debian DLA
EUVD
Github GHSA
Ubuntu USN