An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.
https://lists.debian.org/debian-lts-announce/2025/11/msg00020.html
https://github.com/gevent/gevent/issues/1989
https://github.com/gevent/gevent/commit/2f53c851eaf926767fbac62385615efd4886221c