CVE Tools

Twisted

3 CVEs tracked since 2020. Since Mar 2020, none of them reached CISA KEV.

Twisted CVEs per month

Mar 2020 to Mar 2020. Point at a month, or focus the strip and use the arrow keys.
Twisted CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0330

Products

The products that kept showing up in Twisted's monthly top three, with their CVEs summed over those months.

  1. Twisted31 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Twisted.

  1. CVE-2026-42304Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains7.5
  2. CVE-2024-41810HTML injection in HTTP redirect body6.1
  3. CVE-2024-41671twisted.web has disordered HTTP pipeline response8.3
  4. CVE-2023-46137twisted.web has disordered HTTP pipeline response5.3
  5. CVE-2022-39348Twisted vulnerable to NameVirtualHost Host header injection5.4
  6. CVE-2022-24801HTTP Request Smuggling in twisted.web8.1
  7. CVE-2022-21716Buffer Overflow in Twisted7.5
  8. CVE-2022-21712Cookie and header exposure in twisted7.5
  9. CVE-2022-23607Unsafe handling of user-specified cookies in treq6.5
  10. CVE-2020-10108In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value ...9.8
  11. CVE-2020-10109In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the rem...9.8
  12. CVE-2016-1000111Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_...5.3
  13. CVE-2014-7143Python Twisted 14.0 trustRoot is not respected in HTTP client7.5
  14. CVE-2019-12855In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.7.4
  15. CVE-2019-12387In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.6.1

The record

Peak rank
#160 in Mar 2020
Busiest month shown
Mar 2020, 3 CVEs
Months with a KEV entry
0 since Mar 2020
Monthly snapshots
1 since 2020
Twisted's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store