twisted
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting twisted.
- CVE-2026-42304Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains7.5
- CVE-2024-41810HTML injection in HTTP redirect body6.1
- CVE-2024-41671twisted.web has disordered HTTP pipeline response8.3
- CVE-2023-46137twisted.web has disordered HTTP pipeline response5.3
- CVE-2022-39348Twisted vulnerable to NameVirtualHost Host header injection5.4
- CVE-2022-24801HTTP Request Smuggling in twisted.web8.1
- CVE-2022-21716Buffer Overflow in Twisted7.5
- CVE-2022-21712Cookie and header exposure in twisted7.5
- CVE-2022-23607Unsafe handling of user-specified cookies in treq6.5
- CVE-2020-10108In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value ...9.8
- CVE-2020-10109In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the rem...9.8
- CVE-2016-1000111Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_...5.3
- CVE-2014-7143Python Twisted 14.0 trustRoot is not respected in HTTP client7.5
- CVE-2019-12855In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.7.4
- CVE-2019-12387In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters such as CRLF.6.1