{"id":"CVE-2025-58068","aliases":["GHSA-hw6f-rjfj-j7j7","PYSEC-2026-1350"],"url":"https://o3.security/vulnerability/CVE-2025-58068","summary":"Eventlet affected by HTTP request smuggling in unparsed trailers","details":"### Impact\nThe Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.\n\nThis vulnerability could enable attackers to:\n- Bypass front-end security controls\n- Launch targeted attacks against active site users\n- Poison web caches\n\n### Patches\nProblem has been patched in eventlet 0.40.3.\n\nThe patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.\n\n### Workarounds\nDo not use eventlet.wsgi facing untrusted clients.\n\n### References\n- Patch https://github.com/eventlet/eventlet/pull/1062\n- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj","published":"2025-08-29T21:12:24.534Z","modified":"2026-08-12T03:51:14.331501596Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"eventlet","fixedVersion":"0.40.3"}],"fix":{"url":"https://github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb","label":"eventlet/eventlet@0bfebd1"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00003.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58068.json"},{"type":"ADVISORY","url":"https://github.com/eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58068"},{"type":"FIX","url":"https://github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb"},{"type":"FIX","url":"https://github.com/eventlet/eventlet/pull/1062"},{"type":"PACKAGE","url":"https://github.com/eventlet/eventlet"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:14.331501596Z"}}