{"id":"CVE-2023-41419","aliases":["GHSA-x7m3-jprg-wc5g","PYSEC-2023-177"],"title":"Gevent allows remote attacker to escalate privileges","summary":"Gevent allows remote attacker to escalate privileges","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","vendor":"gevent","product":"gevent","ecosystem":"pip","affected":["gevent < 23.9.0"],"patched":["gevent 23.9.0"],"published":"2023-09-25","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:03.449280541Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-x7m3-jprg-wc5g","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41419"},{"url":"https://github.com/gevent/gevent/issues/1989"},{"url":"https://github.com/gevent/gevent/commit/2f53c851eaf926767fbac62385615efd4886221c"},{"url":"https://github.com/gevent/gevent"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/gevent/PYSEC-2023-177.yaml"},{"url":"https://lists.debian.org/debian-lts-announce/2025/11/msg00020.html"},{"url":"http://www.gevent.org/changelog.html"}],"tags":["osv","pip"],"epss":0.01345,"epssPercentile":0.70169,"ingestedAt":"2026-09-12T03:13:01.739Z","slug":"CVE-2023-41419","body":"## Overview\n\nAn issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.\n\n## Affected packages\n\n- `gevent < 23.9.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `gevent 23.9.0`","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}