eventlet vulnerabilities
CVEs whose affected-version data names the eventlet package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-58068MediumEventlet affected by HTTP request smuggling in unparsed trailers
Eventlet affected by HTTP request smuggling in unparsed trailers
▾ Sunliteventlet · eventletEPSS 0.39%via OSV
CVE-2023-29483Medium· 5.9Potential DoS via the Tudoor mechanism in eventlet and dnspython
Potential DoS via the Tudoor mechanism in eventlet and dnspython
▾ Sunliteventlet · eventletEPSS 1.9%via OSV
CVE-2021-21419Medium· 5.3Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
Improper Handling of Highly Compressed Data (Data Amplification) and Memory Allocation with Excessive Size Value in eventlet
▾ Sunliteventlet · eventletEPSS 1.8%via OSV