SCA: security update for eventlet (GHSA-hw6f-rjfj-j7j7)

medium Tenable Self-Hosted Container Security Plugin ID 435159

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Eventlet is a concurrent networking library for Python. Prior to version 0.40.3, the Eventlet WSGI parser
is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This
vulnerability could enable attackers to, bypass front-end security controls, launch targeted attacks
against active site users, and poison web caches. This problem has been patched in Eventlet 0.40.3 by
dropping trailers which is a breaking change if a backend behind eventlet.wsgi proxy requires trailers. A
workaround involves not using eventlet.wsgi facing untrusted clients. (CVE-2025-58068)

See Also

https://github.com/advisories/GHSA-hw6f-rjfj-j7j7

Plugin Details

Severity: Medium

ID: 435159

Version: Revision 1.12

Type: Local

Family: SCA Checks

Published: 8/30/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.37

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 9.4

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

CVSS Score Source: CVE-2025-58068

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/29/2025

Vulnerability Publication Date: 8/29/2025

Reference Information

CVE: CVE-2025-58068

cwe: CWE-444