Home/Product/twisted
Product

twisted

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-41810
<= 24.3.0
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The twisted.web.util.redirectTo function
6.1MEDIUM
CVE-2023-46137
<= 22.8.0
Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in
5.3MEDIUM
CVE-2022-39348
>= 0.9.4 and < 22.10.0
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a c
5.4MEDIUM
CVE-2022-24801
< 22.4.0
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web
8.1HIGH
CVE-2022-21716
>= 21.7.0 and < 22.2.0
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and ser
7.5HIGH
CVE-2022-21712
>= 11.1.0 and < 22.1.0
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization hea
7.5HIGH
CVE-2020-10109
<= 19.10.0
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chun
9.8CRITICAL
CVE-2020-10108
<= 19.10.0
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers,
9.8CRITICAL
CVE-2016-1000111
< 16.3.1
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI a
5.3MEDIUM
CVE-2014-7143
all versions
Python Twisted 14.0 trustRoot is not respected in HTTP client
7.5HIGH
CVE-2019-12855
<= 19.2.1
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowi
7.4HIGH
CVE-2019-12387
< 19.2.1
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid ch
6.1MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin