<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:34:28.829183+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-14415</id>
    <title>bdu:2025-14415</title>
    <updated>2026-10-04T09:34:29.344377+00:00</updated>
    <content>bdu:2025-14415</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-14415"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-gdbgui-cve-2025-58068</id>
    <title>BREW-gdbgui-CVE-2025-58068 — Eventlet affected by HTTP request smuggling in unparsed trailers</title>
    <updated>2026-10-04T09:34:29.344433+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: gdbgui</p>
<p>### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.</p>
<p>This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches</p>
<p>### Patches
Problem has been patched in eventlet 0.40.3.</p>
<p>The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.</p>
<p>### Workarounds
Do not use eventlet.wsgi facing untrusted clients.</p>
<p>### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-gdbgui-cve-2025-58068"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257578</id>
    <title>EUVD-2026-257578</title>
    <updated>2026-10-04T09:34:29.344476+00:00</updated>
    <content>EUVD-2026-257578</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257578"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58068</id>
    <title>fkie_cve-2025-58068</title>
    <updated>2026-10-04T09:34:29.344490+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-58068"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hw6f-rjfj-j7j7</id>
    <title>GHSA-hw6f-rjfj-j7j7 — Eventlet affected by HTTP request smuggling in unparsed trailers</title>
    <updated>2026-10-04T09:34:29.344514+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: eventlet</p>
<p>### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.</p>
<p>This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches</p>
<p>### Patches
Problem has been patched in eventlet 0.40.3.</p>
<p>The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.</p>
<p>### Workarounds
Do not use eventlet.wsgi facing untrusted clients.</p>
<p>### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hw6f-rjfj-j7j7"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2199</id>
    <title>OESA-2025-2199 — python-eventlet security update</title>
    <updated>2026-10-04T09:34:29.344540+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-eventlet</p>
<p>Eventlet is a concurrent networking library for Python that allows you to change how you run your code, not how you write it.

Security Fix(es):</p>
<p>Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.(CVE-2025-58068)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15507-1</id>
    <title>openSUSE-SU-2025:15507-1 — python311-eventlet-0.40.3-1.1 on GA media</title>
    <updated>2026-10-04T09:34:29.344563+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-eventlet-0.40.3-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15507-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1350</id>
    <title>PYSEC-2026-1350 — Eventlet affected by HTTP request smuggling in unparsed trailers</title>
    <updated>2026-10-04T09:34:29.344595+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: eventlet</p>
<p>### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.</p>
<p>This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches</p>
<p>### Patches
Problem has been patched in eventlet 0.40.3.</p>
<p>The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.</p>
<p>### Workarounds
Do not use eventlet.wsgi facing untrusted clients.</p>
<p>### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1350"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:0663</id>
    <title>RHSA-2026:0663 — Red Hat Security Advisory: OpenShift Container Platform 4.20.11 bug fix and security update</title>
    <updated>2026-10-04T09:34:29.344648+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python-eventlet: Eventlet HTTP request smuggling golang: archive/tar: Unbounded allocation when parsing GNU sparse map</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:0663"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03051-1</id>
    <title>SUSE-SU-2025:03051-1 — Security update for python-eventlet</title>
    <updated>2026-10-04T09:34:29.344682+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-eventlet</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03051-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58068</id>
    <title>UBUNTU-CVE-2025-58068</title>
    <updated>2026-10-04T09:34:29.344698+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: python-eventlet, Ubuntu:18.04:LTS: python-eventlet, Ubuntu:Pro:20.04:LTS: python-eventlet, Ubuntu:22.04:LTS: python-eventlet, Ubuntu:24.04:LTS: python-eventlet, Ubuntu:25.10: python-eventlet, Ubuntu:26.04:LTS: python-eventlet</p>
<p>Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58068"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0408</id>
    <title>WID-SEC-W-2026-0408 — Red Hat OpenStack Services auf OpenShift (python-eventlet, keystone): Mehrere Schwachstellen</title>
    <updated>2026-10-04T09:34:29.344731+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenStack Services auf OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder Berechtigungen zu erweitern.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0408"/>
  </entry>
</feed>
