Critical severity9.1NVD Advisory· Published Aug 29, 2025· Updated Jun 17, 2026
CVE-2025-58068
CVE-2025-58068
Description
Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
eventletPyPI | < 0.40.3 | 0.40.3 |
Affected products
9- ghsa-coords7 versionspkg:pypi/eventletpkg:rpm/opensuse/python-eventlet&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python-eventlet&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-eventlet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/python-eventlet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7pkg:rpm/suse/python-eventlet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP6pkg:rpm/suse/python-eventlet&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7
< 0.40.3+ 6 more
- (no CPE)range: < 0.40.3
- (no CPE)range: < 0.33.3-150400.5.6.1
- (no CPE)range: < 0.40.3-1.1
- (no CPE)range: < 0.26.1-150300.3.3.1
- (no CPE)range: < 0.26.1-150300.3.3.1
- (no CPE)range: < 0.33.3-150400.5.6.1
- (no CPE)range: < 0.33.3-150400.5.6.1
Patches
Vulnerability mechanics
References
6- github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fbnvdPatchWEB
- github.com/advisories/GHSA-hw6f-rjfj-j7j7ghsaADVISORY
- github.com/eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-58068ghsaADVISORY
- github.com/eventlet/eventlet/pull/1062nvdIssue TrackingWEB
- lists.debian.org/debian-lts-announce/2025/09/msg00003.htmlnvdWEB
News mentions
0No linked articles in our index yet.