Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2023-41419: gevent could let attackers run code on your server
CVE-2023-41419 · published 1 day ago
Summary
The Python library gevent has a flaw that could allow an attacker to execute their own code on a system that uses the library. This could lead to unauthorized access or data manipulation. Update gevent to the latest version released by the maintainers to close the risk.
What to do
- Update denis bilenko gevent to version 23.9.0.
- Update gevent to version 21.12.0+aikido.3.
- Update gevent gevent to version 23.9.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| pip | denis bilenko | gevent |
< 23.9.0 Fix: upgrade to 23.9.0
|
| – | gevent | gevent |
< 23.9.0 cpe:2.3:a:gevent:gevent:*:*:*:*:*:*:*:* |
| Root:PyPI | – | gevent |
< 21.12.0+aikido.3 Fix: upgrade to 21.12.0+aikido.3
|
Original advisory text
CVE-2023-41419 in gevent - Patched by Root
Root has patched CVE-2023-41419 in the gevent package for Root:PyPI. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-41419
- https://github.com/gevent/gevent/issues/1989
- https://github.com/gevent/gevent/commit/2f53c851eaf926767fbac62385615efd4886221c
- https://github.com/pypa/advisory-database/tree/main/vulns/gevent/PYSEC-2023-177....
- http://www.gevent.org/changelog.html
- https://lists.debian.org/debian-lts-announce/2025/11/msg00020.html
- https://github.com/advisories/GHSA-x7m3-jprg-wc5g
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically (estimated)
- Gives an attacker full control (estimated)
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta