Twisted
3 CVEs tracked since 2020. Since Mar 2020, none of them reached CISA KEV.
Twisted CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2020-03 | 3 | 0 |
Products
The products that kept showing up in Twisted's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Twisted.
- CVE-2026-42304Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains7.5
- CVE-2024-41810HTML injection in HTTP redirect body6.1
- CVE-2024-41671twisted.web has disordered HTTP pipeline response8.3
- CVE-2023-46137twisted.web has disordered HTTP pipeline response5.3
- CVE-2022-39348Twisted vulnerable to NameVirtualHost Host header injection5.4
- CVE-2022-24801HTTP Request Smuggling in twisted.web8.1
- CVE-2022-21716Buffer Overflow in Twisted7.5
- CVE-2022-21712Cookie and header exposure in twisted7.5
- CVE-2022-23607Unsafe handling of user-specified cookies in treq6.5
- CVE-2020-10108In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value ...9.8
- CVE-2020-10109In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the rem...9.8
- CVE-2016-1000111Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_...5.3
- CVE-2014-7143Python Twisted 14.0 trustRoot is not respected in HTTP client7.5
- CVE-2019-12855In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.7.4
- CVE-2019-12387In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.6.1
The record
- Peak rank
- #160 in Mar 2020
- Busiest month shown
- Mar 2020, 3 CVEs
- Months with a KEV entry
- 0 since Mar 2020
- Monthly snapshots
- 1 since 2020