PatchSiren

twisted CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM twisted CVE published 2026-10-07

CVE-2026-106454

The CVE record was published on 2026-10-07T16:18:30.000Z and has not been modified since then. The NVD entry is currently null. This CVE record details a vulnerability in Twisted's IMAP implementation, specifically in the `wildcardToRegexp()` function, which is vulnerable to ReDoS attacks. IMAP service operators and administrators should assess their exposure and prioritize verification of their configura [truncated]

HIGH twisted CVE published 2026-05-13

CVE-2026-42304

CVE-2026-42304 is a high-severity Denial of Service (DoS) vulnerability in Twisted, an event-based Python framework for internet applications. The flaw exists in the twisted.names module prior to version 26.4.0rc2 and stems from resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression po [truncated]