Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2023-41419: gevent could let attackers run code on your server

CVE-2023-41419 · published 1 day ago
Summary

The Python library gevent has a flaw that could allow an attacker to execute their own code on a system that uses the library. This could lead to unauthorized access or data manipulation. Update gevent to the latest version released by the maintainers to close the risk.

What to do
  • Update denis bilenko gevent to version 23.9.0.
  • Update gevent to version 21.12.0+aikido.3.
  • Update gevent gevent to version 23.9.0 or later.
Affected software
Ecosystem VendorProductAffected versions
pip denis bilenko gevent < 23.9.0
Fix: upgrade to 23.9.0
– gevent gevent < 23.9.0
cpe:2.3:a:gevent:gevent:*:*:*:*:*:*:*:*
Root:PyPI – gevent < 21.12.0+aikido.3
Fix: upgrade to 21.12.0+aikido.3
Original advisory text
CVE-2023-41419 in gevent - Patched by Root
Root has patched CVE-2023-41419 in the gevent package for Root:PyPI. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.8 Critical
Exploitation
2% chance of attack within 30 days
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta