Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-58068

29
FAUCET Score

CVE-2025-58068 is a critical HTTP Request Smuggling vulnerability affecting Eventlet, a Python concurrent networking library, specifically versions prior to 0.40.3. This flaw, rated 9.1 CVSS, stems from improper handling of HTTP trailer sections, allowing unauthenticated attackers to bypass security controls, target users, and poison web caches. While no active exploitation, public exploit code, or significant community discussion has been observed, the high severity warrants immediate patching to version 0.40.3 or implementing the recommended workaround of not exposing eventlet.wsgi to untrusted clients.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.40.3CPE matchmatch criteria
cpe:2.3:a:eventlet:eventlet:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 6th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: eventletFixed in: 0.40.3
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Services on OpenShift 18.0Fixed in: python-eventlet-0:0.33.1-7.el9ost
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: openshift4/ose-ironic-agent-rhel9:sha256:5a30a1eb1091054facc200e9518afd543192758a9bf2e664e44cfc531e10978b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: openshift4/ose-ironic-rhel9:sha256:9dd169e3a46ae8eaf47028070e752a308cec0418f8102dbedadd4210b867e706
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: openshift4/ose-ironic-agent-rhel9:sha256:e1f1327c9f5bcbab1432f1de7a150ec7d86d93fe01117e459fd95eec0a908f70
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: openshift4/ose-ironic-rhel9:sha256:0977783506ac5f17681e8aa7362676944c02a8b87dc7c39c83669ffe8ee78a86
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: openshift4/ose-ironic-agent-rhel9:sha256:a629a70723438621732aaafbe799b0f92c2d3a07e9028e22ee2ff3bceb911bac
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: openshift4/ose-ironic-rhel9:sha256:9e9525d31895ad7e9a1ff753e0895f7d845a36294f88fab8041f2f3deefa6608
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: openshift4/ose-ironic-agent-rhel9:sha256:c42e80ae7ba48b0f92351d95ac4ac1b7e41273653388286ebad5890d16af1232
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: openshift4/ose-ironic-rhel9:sha256:21165c7921a56c93704c250089a5c2fec5970447a816d94aacd39864fc3944cb
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: openshift4/ose-ironic-agent-rhel9:sha256:5969111957d6c24152ebd937962733d7ee93fcbc52c6b0a56963b5a1c9dc0d15
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: openshift4/ose-ironic-rhel9:sha256:9232c8af8e0ba7a15fabd923feef6dc1d3f7e2a740ef0c277009f348cc0accb4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.19Fixed in: openshift4/ose-ironic-agent-rhel9:sha256:d001d8b46a99c6beba5275167af10352e62a7fe9c7316eaa82175034e5413674
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.19Fixed in: openshift4/ose-ironic-rhel9:sha256:ee3d999e8db2fb41768aeb371e086b241176a0a5135dd76db3c713096aef0baf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.2Fixed in: openshift4/ose-ironic-agent-rhel9:sha256:ee95937760fb08c244783b3c595362a043bb900b1cc0103e2e38917dfe09c802
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.2Fixed in: openshift4/ose-ironic-rhel9:sha256:3d27e2c463eede647237c9eb1b5f320ca064accb83c82316325b25c3f74ffe79
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.21Fixed in: openshift4/ose-ironic-rhel9:sha256:3281b909de7dfc5bf3c746e3e8ab05fec49fc8aa83dc8156e616a59c41ee923c
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: python-eventlet

Vendor Advisories (2)

redhatCVE-2025-58068Moderate

python-eventlet: Eventlet HTTP request smuggling

Aug 29, 2025
pipGHSA-hw6f-rjfj-j7j7medium

Eventlet affected by HTTP request smuggling in unparsed trailers

Aug 29, 2025

References

lists.debian.org / debian-lts-announce/2025/09/msg00003.html
github.com / eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb
Patch
github.com / eventlet/eventlet/pull/1062
Issue Tracking
github.com / eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7
Vendor Advisory