<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:08:58 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-14415</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-14415</link>
      <description>bdu:2025-14415</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-14415</guid>
    </item>
    <item>
      <title>BREW-gdbgui-CVE-2025-58068 — Eventlet affected by HTTP request smuggling in unparsed trailers</title>
      <link>https://cve.radiocsirt.org/vuln/brew-gdbgui-cve-2025-58068</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: gdbgui&lt;/p&gt;
&lt;p&gt;### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.&lt;/p&gt;
&lt;p&gt;This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches&lt;/p&gt;
&lt;p&gt;### Patches
Problem has been patched in eventlet 0.40.3.&lt;/p&gt;
&lt;p&gt;The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.&lt;/p&gt;
&lt;p&gt;### Workarounds
Do not use eventlet.wsgi facing untrusted clients.&lt;/p&gt;
&lt;p&gt;### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: gdbgui&lt;/p&gt;
&lt;p&gt;### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.&lt;/p&gt;
&lt;p&gt;This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches&lt;/p&gt;
&lt;p&gt;### Patches
Problem has been patched in eventlet 0.40.3.&lt;/p&gt;
&lt;p&gt;The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.&lt;/p&gt;
&lt;p&gt;### Workarounds
Do not use eventlet.wsgi facing untrusted clients.&lt;/p&gt;
&lt;p&gt;### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-gdbgui-cve-2025-58068</guid>
    </item>
    <item>
      <title>EUVD-2026-257578</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-257578</link>
      <description>EUVD-2026-257578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-257578</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58068</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58068</link>
      <description>&lt;p&gt;Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58068</guid>
    </item>
    <item>
      <title>GHSA-hw6f-rjfj-j7j7 — Eventlet affected by HTTP request smuggling in unparsed trailers</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hw6f-rjfj-j7j7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: eventlet&lt;/p&gt;
&lt;p&gt;### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.&lt;/p&gt;
&lt;p&gt;This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches&lt;/p&gt;
&lt;p&gt;### Patches
Problem has been patched in eventlet 0.40.3.&lt;/p&gt;
&lt;p&gt;The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.&lt;/p&gt;
&lt;p&gt;### Workarounds
Do not use eventlet.wsgi facing untrusted clients.&lt;/p&gt;
&lt;p&gt;### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: eventlet&lt;/p&gt;
&lt;p&gt;### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.&lt;/p&gt;
&lt;p&gt;This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches&lt;/p&gt;
&lt;p&gt;### Patches
Problem has been patched in eventlet 0.40.3.&lt;/p&gt;
&lt;p&gt;The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.&lt;/p&gt;
&lt;p&gt;### Workarounds
Do not use eventlet.wsgi facing untrusted clients.&lt;/p&gt;
&lt;p&gt;### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hw6f-rjfj-j7j7</guid>
    </item>
    <item>
      <title>OESA-2025-2199 — python-eventlet security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2199</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-eventlet&lt;/p&gt;
&lt;p&gt;Eventlet is a concurrent networking library for Python that allows you to change how you run your code, not how you write it.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.(CVE-2025-58068)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-eventlet&lt;/p&gt;
&lt;p&gt;Eventlet is a concurrent networking library for Python that allows you to change how you run your code, not how you write it.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.(CVE-2025-58068)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2199</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15507-1 — python311-eventlet-0.40.3-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15507-1</link>
      <description>&lt;p&gt;python311-eventlet-0.40.3-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-eventlet-0.40.3-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15507-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1350 — Eventlet affected by HTTP request smuggling in unparsed trailers</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1350</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: eventlet&lt;/p&gt;
&lt;p&gt;### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.&lt;/p&gt;
&lt;p&gt;This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches&lt;/p&gt;
&lt;p&gt;### Patches
Problem has been patched in eventlet 0.40.3.&lt;/p&gt;
&lt;p&gt;The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.&lt;/p&gt;
&lt;p&gt;### Workarounds
Do not use eventlet.wsgi facing untrusted clients.&lt;/p&gt;
&lt;p&gt;### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: eventlet&lt;/p&gt;
&lt;p&gt;### Impact
The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections.&lt;/p&gt;
&lt;p&gt;This vulnerability could enable attackers to:
- Bypass front-end security controls
- Launch targeted attacks against active site users
- Poison web caches&lt;/p&gt;
&lt;p&gt;### Patches
Problem has been patched in eventlet 0.40.3.&lt;/p&gt;
&lt;p&gt;The patch just drops trailers. If a backend behind eventlet.wsgi proxy requires trailers, then this patch BREAKS your setup.&lt;/p&gt;
&lt;p&gt;### Workarounds
Do not use eventlet.wsgi facing untrusted clients.&lt;/p&gt;
&lt;p&gt;### References
- Patch https://github.com/eventlet/eventlet/pull/1062
- This issue is similar to https://github.com/advisories/GHSA-9548-qrrj-x5pj&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1350</guid>
    </item>
    <item>
      <title>RHSA-2026:0663 — Red Hat Security Advisory: OpenShift Container Platform 4.20.11 bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:0663</link>
      <description>&lt;p&gt;python-eventlet: Eventlet HTTP request smuggling golang: archive/tar: Unbounded allocation when parsing GNU sparse map&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-eventlet: Eventlet HTTP request smuggling golang: archive/tar: Unbounded allocation when parsing GNU sparse map&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:0663</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03051-1 — Security update for python-eventlet</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03051-1</link>
      <description>&lt;p&gt;Security update for python-eventlet&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-eventlet&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03051-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-58068</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58068</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-eventlet, Ubuntu:18.04:LTS: python-eventlet, Ubuntu:Pro:20.04:LTS: python-eventlet, Ubuntu:22.04:LTS: python-eventlet, Ubuntu:24.04:LTS: python-eventlet, Ubuntu:25.10: python-eventlet, Ubuntu:26.04:LTS: python-eventlet&lt;/p&gt;
&lt;p&gt;Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: python-eventlet, Ubuntu:18.04:LTS: python-eventlet, Ubuntu:Pro:20.04:LTS: python-eventlet, Ubuntu:22.04:LTS: python-eventlet, Ubuntu:24.04:LTS: python-eventlet, Ubuntu:25.10: python-eventlet, Ubuntu:26.04:LTS: python-eventlet&lt;/p&gt;
&lt;p&gt;Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A workaround involves not using eventlet.wsgi facing untrusted clients.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58068</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0408 — Red Hat OpenStack Services auf OpenShift (python-eventlet, keystone): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0408</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenStack Services auf OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder Berechtigungen zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat OpenStack Services auf OpenShift ausnutzen, um Sicherheitsvorkehrungen zu umgehen oder Berechtigungen zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0408</guid>
    </item>
  </channel>
</rss>
