PYSEC-2026-1350
Eventlet affected by HTTP request smuggling in unparsed trailers
Quick fix
PYSEC-2026-1350 — eventlet: upgrade to the fixed version with the command below.
pip install --upgrade 'eventlet>=0.40.3'Details
### Impact The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.
This vulnerability could enable attackers to: - Bypass front-end security controls - Launch targeted attacks against active site users - Poison web caches
### Patches Problem has been patched in eventlet 0.40.3.
The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.
### Workarounds Do not use eventlet.wsgi facing untrusted clients.
### References - Patch https://github.com/eventlet/eventlet/pull/1062 - This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-58068[ADVISORY]
- https://github.com/eventlet/eventlet/pull/1062[WEB]
- https://github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb[WEB]
- https://github.com/eventlet/eventlet[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2025/09/msg00003.html[WEB]
- https://pypi.org/project/eventlet[PACKAGE]
- https://github.com/advisories/GHSA-hw6f-rjfj-j7j7[ADVISORY]