VDB
RHSA-2026%3A1062
RHSA-2026%3A1062
PUBLISHED
CVSS 6.5 MEDIUM
A request smuggling flaw was found in the Eventlet PyPI library. The Eventlet WSGI parser is vulnerable to HTTP Request Smuggling due to improper handling of HTTP trailer sections. This vulnerability allows attackers to bypass front-end security controls, launch targeted attacks against active site users, and poison web caches.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | registry.redhat.io/openshift4/ose-csi-driver-manila-rhel9-operator@sha256:4c9bfdc66ceaf66bc9b66d332a5579b412cc560200b82793a37996bd1a828734_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | *, registry.redhat.io/openshift4/ose-csi-driver-manila-rhel9-operator@sha256:4c9bfdc66ceaf66bc9b66d332a5579b412cc560200b82793a37996bd1a828734_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-agent-installer-utils-rhel9@sha256:f71086b942e1399a7637de656443023593b70dd12c4667c9d615c5c7920299ca_s390x as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-agent-installer-utils-rhel9@sha256:f71086b942e1399a7637de656443023593b70dd12c4667c9d615c5c7920299ca_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:7b26569a85b4ef6cadf9670d3472b7c9ab15b109bcda9cb73dcc66e8230df4f4_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-agent-installer-api-server-rhel9@sha256:7b26569a85b4ef6cadf9670d3472b7c9ab15b109bcda9cb73dcc66e8230df4f4_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-network-metrics-daemon-rhel9@sha256:e38f330016b2e81eca6f69397ad57a5d0348f2d2f2c3522307b35aadf8b5ddb9_s390x as a component of Red Hat OpenShift Container Platform 4.18 | * |
| Red Hat | registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:233b59eac6fca6ccd87ab66f83799a4684116681e840103def6497241e6cfd23_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-agent-installer-node-agent-rhel9@sha256:233b59eac6fca6ccd87ab66f83799a4684116681e840103def6497241e6cfd23_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:96a6495fa5423c74755f90b16c9f7f036ad9d392a7cef288d66066714ba1afef_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | *, registry.redhat.io/openshift4/ose-aws-cluster-api-controllers-rhel9@sha256:96a6495fa5423c74755f90b16c9f7f036ad9d392a7cef288d66066714ba1afef_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-haproxy-router-rhel9@sha256:6b318889972c37662382a2905888bb3f1cfd71a433b6afa3504cc12f3c6fa6eb_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | *, registry.redhat.io/openshift4/ose-haproxy-router-rhel9@sha256:6b318889972c37662382a2905888bb3f1cfd71a433b6afa3504cc12f3c6fa6eb_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-storage-rhel9-operator@sha256:9617d07f9516a6379b20ba8f01065096ed90a9d76afa5ab45e36bbdc03a10c06_s390x as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-cluster-storage-rhel9-operator@sha256:9617d07f9516a6379b20ba8f01065096ed90a9d76afa5ab45e36bbdc03a10c06_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-ironic-static-ip-manager-rhel9@sha256:e55a15f93eedbf7b0e13fea4d3ac9b891453f854d5294a891c1b9a848c6ef54f_arm64 as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-ironic-static-ip-manager-rhel9@sha256:e55a15f93eedbf7b0e13fea4d3ac9b891453f854d5294a891c1b9a848c6ef54f_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-etcd-rhel9@sha256:cc9bf05482fc6e6265b99d15af471c07833443e3cf570f98fe9485320a91160f_ppc64le as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-etcd-rhel9@sha256:cc9bf05482fc6e6265b99d15af471c07833443e3cf570f98fe9485320a91160f_ppc64le |
| Red Hat | registry.redhat.io/openshift4/ose-haproxy-router-rhel9@sha256:4f9bd383efba6e1bcd94b7a665177d408a9d09ed6abc91b7c1f5096cc9c716d7_s390x as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-haproxy-router-rhel9@sha256:4f9bd383efba6e1bcd94b7a665177d408a9d09ed6abc91b7c1f5096cc9c716d7_s390x |
| Red Hat | registry.redhat.io/openshift4/ose-thanos-rhel9@sha256:86d47b2746de823e60068255722d2c0f1ff9d327b2865071a4f2f1e08b1f4ee9_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | *, registry.redhat.io/openshift4/ose-thanos-rhel9@sha256:86d47b2746de823e60068255722d2c0f1ff9d327b2865071a4f2f1e08b1f4ee9_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-powervs-block-csi-driver-rhel9-operator@sha256:ce32ae8e1e42da3e4e2440a721704db7039e66b8c1fdaebaa42cf8706f43d9e1_ppc64le as a component of Red Hat OpenShift Container Platform 4.18 | * |
| Red Hat | registry.redhat.io/openshift4/ose-cluster-openshift-controller-manager-rhel9-operator@sha256:f353131d8a1223db7f637c9851016b3a348d80c2b2be663a2db6d01e14ddca88_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-cluster-openshift-controller-manager-rhel9-operator@sha256:f353131d8a1223db7f637c9851016b3a348d80c2b2be663a2db6d01e14ddca88_amd64, * |
| Red Hat | registry.redhat.io/openshift4/ose-powervs-machine-controllers-rhel9@sha256:ff84e7b914e4318aca775db8601d5b04ed6eb240d4d116f6505e04cb947c4a3c_ppc64le as a component of Red Hat OpenShift Container Platform 4.18 | * |
| Red Hat | registry.redhat.io/openshift4/ose-openstack-cinder-csi-driver-rhel9-operator@sha256:770e169283c6dc690b2e5ad6560c43ace5897760f45ba4e0cbf006a75def23b1_arm64 as a component of Red Hat OpenShift Container Platform 4.18 | * |
| Red Hat | registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel9@sha256:c45d47b1c09d848db11c0e411048b01c10424d13c7ef1763f7ff4114793403a1_arm64 as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel9@sha256:c45d47b1c09d848db11c0e411048b01c10424d13c7ef1763f7ff4114793403a1_arm64 |
| Red Hat | registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:9232c8af8e0ba7a15fabd923feef6dc1d3f7e2a740ef0c277009f348cc0accb4_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:9232c8af8e0ba7a15fabd923feef6dc1d3f7e2a740ef0c277009f348cc0accb4_amd64, * |
| Red Hat | registry.redhat.io/openshift4/openshift-route-controller-manager-rhel9@sha256:0871b6c16b38a2eda5d1c89fd75079aff0775224307e940557e6fda6ba229f38_amd64 as a component of Red Hat OpenShift Container Platform 4.18 | registry.redhat.io/openshift4/openshift-route-controller-manager-rhel9@sha256:0871b6c16b38a2eda5d1c89fd75079aff0775224307e940557e6fda6ba229f38_amd64 |
| Red Hat | registry.redhat.io/openshift4/ose-libvirt-machine-controllers-rhel9@sha256:a5349be7d33bb9d7d94718e63db975b1bc65c355bebd77269e5bc1f3affa6892_arm64 as a component of Red Hat OpenShift Container Platform 4.18 | *, * |
…and 1296 more
Timeline
- Feb 3, 2026 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2026:1062 advisory
- https://access.redhat.com/security/cve/CVE-2025-58068 advisory
- https://access.redhat.com/security/cve/CVE-2025-65637 advisory
- https://access.redhat.com/security/updates/classification/ advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_1062.json advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2391958 issue
- https://www.cve.org/CVERecord?id=CVE-2025-58068 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-58068 advisory
- https://github.com/eventlet/eventlet/commit/0bfebd1117d392559e25b4bfbfcc941754de88fb advisory
- https://github.com/eventlet/eventlet/pull/1062 advisory
- https://github.com/eventlet/eventlet/security/advisories/GHSA-hw6f-rjfj-j7j7 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418900 issue
- https://www.cve.org/CVERecord?id=CVE-2025-65637 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-65637 advisory
- https://github.com/mjuanxd/logrus-dos-poc exploit
- https://github.com/mjuanxd/logrus-dos-poc/blob/main/README.md exploit
- https://github.com/sirupsen/logrus/issues/1370 advisory
- https://github.com/sirupsen/logrus/pull/1376 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.8.3 advisory
- https://github.com/sirupsen/logrus/releases/tag/v1.9.1 advisory
…and 2 more