PYSEC-2026-1350

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/eventlet/PYSEC-2026-1350.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-1350
Aliases
Published
2026-07-07T16:03:02.778128Z
Modified
2026-07-07T17:46:41.634328928Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Eventlet affected by HTTP request smuggling in unparsed trailers
Details

Impact

The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.

This vulnerability could enable attackers to: - Bypass front-end security controls - Launch targeted attacks against active site users - Poison web caches

Patches

Problem has been patched in eventlet 0.40.3.

The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.

Workarounds

Do not use eventlet.wsgi facing untrusted clients.

References

  • Patch https://github.com/eventlet/eventlet/pull/1062
  • This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj
References

Affected packages

PyPI / eventlet

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.40.3

Affected versions

0.*
0.2
0.5.3
0.6.1
0.7
0.8
0.8.16
0.9.17
0.10.0
0.11.0
0.12.1
0.13.0
0.14.0
0.15.2
0.16.1
0.17.4
0.18.2
0.18.3
0.18.4
0.19.0
0.20.0
0.20.1
0.21.0
0.22.0
0.22.1
0.23.0
0.24.0
0.24.1
0.25.0
0.25.1
0.25.2
0.26.0
0.26.1
0.27.0
0.28.0
0.28.1
0.29.0
0.29.1
0.30.0
0.30.1
0.30.2
0.30.3
0.31.0
0.31.1
0.32.0
0.33.0
0.33.1
0.33.2
0.33.3
0.34.1
0.34.2
0.34.3
0.35.0
0.35.1
0.35.2
0.36.0
0.36.1
0.37.0
0.38.0
0.38.1
0.38.2
0.39.0
0.39.1
0.40.0
0.40.1
0.40.2

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/eventlet/PYSEC-2026-1350.yaml"