{"id":"CVE-2025-58068","aliases":["GHSA-hw6f-rjfj-j7j7","PYSEC-2026-1350"],"title":"Eventlet affected by HTTP request smuggling in unparsed trailers","summary":"Eventlet affected by HTTP request smuggling in unparsed trailers","severity":"medium","vendor":"eventlet","product":"eventlet","ecosystem":"pip","affected":["eventlet < 0.40.3"],"patched":["eventlet 0.40.3"],"published":"2025-08-29","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-hw6f-rjfj-j7j7","references":[{"url":"https://github.com/eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58068"},{"url":"https://github.com/eventlet/eventlet/pull/1062"},{"url":"https://github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb"},{"url":"https://github.com/eventlet/eventlet"},{"url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00003.html"}],"tags":["osv","pip"],"epss":0.0039,"epssPercentile":0.3023,"ingestedAt":"2026-07-08T18:25:50.326Z","slug":"CVE-2025-58068","body":"## Overview\n\n### Impact\nThe Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.\n\nThis vulnerability could enable attackers to:\n- Bypass front-end security controls\n- Launch targeted attacks against active site users\n- Poison web caches\n\n### Patches\nProblem has been patched in eventlet 0.40.3.\n\nThe patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.\n\n### Workarounds\nDo not use eventlet.wsgi facing untrusted clients.\n\n### References\n- Patch https://github.com/eventlet/eventlet/pull/1062\n- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj\n\n## Affected packages\n\n- `eventlet < 0.40.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `eventlet 0.40.3`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}