PT-2025-35318 · Eventlet+4 · Eventlet+4
Sebastianosrt
·
Published
2025-01-01
·
Updated
2026-01-30
·
CVE-2025-58068
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Eventlet versions prior to 0.40.3
Description
The Eventlet WSGI parser is susceptible to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This issue could allow attackers to bypass front-end security controls, launch targeted attacks against active site users, and poison web caches.
Recommendations
Update to Eventlet version 0.40.3 or later.
As a workaround, avoid using Eventlet WSGI when facing untrusted clients.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Eventlet
Linuxmint
Red Os
Ubuntu