VDB
Sign up
—

PYSEC-2026-1350

Eventlet affected by HTTP request smuggling in unparsed trailers

Quick fix

PYSEC-2026-1350 — eventlet: upgrade to the fixed version with the command below.

pip install --upgrade 'eventlet>=0.40.3'

Details

### Impact The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.

This vulnerability could enable attackers to: - Bypass front-end security controls - Launch targeted attacks against active site users - Poison web caches

### Patches Problem has been patched in eventlet 0.40.3.

The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.

### Workarounds Do not use eventlet.wsgi facing untrusted clients.

### References - Patch https://github.com/eventlet/eventlet/pull/1062 - This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/eventlet
Introduced in: 0Fixed in: 0.40.3
Fixpip install --upgrade 'eventlet>=0.40.3'

References