CVE-2025-58068

EUVD-2025-26392
Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.
HTTP Request/Response Smuggling
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 32.01%
Affected Products (NVD)
VendorProductVersion
eventleteventlet
𝑥
< 0.40.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-eventlet
bookworm
no-dsa
bullseye
vulnerable
bullseye (security)
0.26.1-7+deb11u2
fixed
forky
0.40.4-1
fixed
sid
0.40.4-4
fixed
trixie
0.39.1-2+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-eventlet
bionic
needs-triage
focal
Fixed 0.25.1-2ubuntu1.1+esm2
released
jammy
Fixed 0.30.2-5ubuntu2.2
released
noble
Fixed 0.35.2-0ubuntu1.1
released
plucky
Fixed 0.39.0-0ubuntu1.1
released
questing
Fixed 0.39.0-0ubuntu2
released
resolute
Fixed 0.39.0-0ubuntu2
released
xenial
needs-triage