Eventlet is a lightweight Python networking library that provides concurrency and asynchronous I/O primitives, with its vulnerability footprint concentrated in the single product of that name. The observed weakness classes center on HTTP protocol handling and resource management issues, including HTTP request/response smuggling, DNS trust validation, and uncontrolled resource consumption—attack surface areas characteristic of network-facing I/O libraries that parse external input. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eventlet over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58068CRITICAL Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP t | Aug 29, 2025 | 9.1 | 29 | NO | NO |
CVE-2023-29483HIGH eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP a | Apr 11, 2024 | 7.0 | 22 | NO | NO |
CVE-2021-21419MEDIUM Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memo | May 7, 2021 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eventlet.
Media articles that mention a CVE ID that affects a product developed by Eventlet — matched by CVE ID, not by vendor name.