{"id":"PYSEC-2026-1350","summary":"Eventlet affected by HTTP request smuggling in unparsed trailers","details":"### Impact\nThe Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.\n\nThis vulnerability could enable attackers to:\n- Bypass front-end security controls\n- Launch targeted attacks against active site users\n- Poison web caches\n\n### Patches\nProblem has been patched in eventlet 0.40.3.\n\nThe patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.\n\n### Workarounds\nDo not use eventlet.wsgi facing untrusted clients.\n\n### References\n- Patch https://github.com/eventlet/eventlet/pull/1062\n- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj","aliases":["CVE-2025-58068","GHSA-hw6f-rjfj-j7j7"],"modified":"2026-07-07T17:46:41.634328928Z","published":"2026-07-07T16:03:02.778128Z","references":[{"type":"WEB","url":"https://github.com/eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58068"},{"type":"WEB","url":"https://github.com/eventlet/eventlet/pull/1062"},{"type":"WEB","url":"https://github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb"},{"type":"PACKAGE","url":"https://github.com/eventlet/eventlet"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00003.html"},{"type":"PACKAGE","url":"https://pypi.org/project/eventlet"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hw6f-rjfj-j7j7"}],"affected":[{"package":{"name":"eventlet","ecosystem":"PyPI","purl":"pkg:pypi/eventlet"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.40.3"}]}],"versions":["0.10.0","0.11.0","0.12.1","0.13.0","0.14.0","0.15.2","0.16.1","0.17.4","0.18.2","0.18.3","0.18.4","0.19.0","0.2","0.20.0","0.20.1","0.21.0","0.22.0","0.22.1","0.23.0","0.24.0","0.24.1","0.25.0","0.25.1","0.25.2","0.26.0","0.26.1","0.27.0","0.28.0","0.28.1","0.29.0","0.29.1","0.30.0","0.30.1","0.30.2","0.30.3","0.31.0","0.31.1","0.32.0","0.33.0","0.33.1","0.33.2","0.33.3","0.34.1","0.34.2","0.34.3","0.35.0","0.35.1","0.35.2","0.36.0","0.36.1","0.37.0","0.38.0","0.38.1","0.38.2","0.39.0","0.39.1","0.40.0","0.40.1","0.40.2","0.5.3","0.6.1","0.7","0.8","0.8.16","0.9.17"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/eventlet/PYSEC-2026-1350.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}