Explore top 10 tips to secure your open-source projects now. Read More
×Twisted could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8380-1 June 03, 2026 twisted vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Twisted could be made to crash if it received specially crafted network traffic. Software Description: - twisted: Event-based framework for internet applications Details: It was discovered that Twisted incorrectly handled DNS name decompression. A remote attacker could possibly use this issue to cause Twisted to consume excessive resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-twisted 25.5.0-5ubuntu0.1 Ubuntu 25.10 python3-twisted 24.11.0-1ubuntu0.1 Ubuntu 24.04 LTS python3-twisted 24.3.0-1ubuntu0.2 Ubuntu 22.04 LTS python3-twisted 22.1.0-2ubuntu2.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8380-1 CVE-2026-42304 Package Information: https://launchpad.net/ubuntu/+source/twisted/25.5.0-5ubuntu0.1 https://launchpad.net/ubuntu/+source/twisted/24.11.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/twisted/24.3.0-1ubuntu0.2 https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.7 . Twisted can crash from crafted network traffic on Ubuntu. Updates available for multiple versions. Patch now.. Twisted update, Ubuntu security, denial of service patch. . Severity: moderate. LinuxSecurity.com Team
Twisted could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-8380-1 June 03, 2026 twisted vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Twisted could be made to crash if it received specially crafted network traffic. Software Description: - twisted: Event-based framework for internet applications Details: It was discovered that Twisted incorrectly handled DNS name decompression. A remote attacker could possibly use this issue to cause Twisted to consume excessive resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-twisted 25.5.0-5ubuntu0.1 Ubuntu 25.10 python3-twisted 24.11.0-1ubuntu0.1 Ubuntu 24.04 LTS python3-twisted 24.3.0-1ubuntu0.2 Ubuntu 22.04 LTS python3-twisted 22.1.0-2ubuntu2.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8380-1 CVE-2026-42304 Package Information: https://launchpad.net/ubuntu/+source/twisted/25.5.0-5ubuntu0.1 https://launchpad.net/ubuntu/+source/twisted/24.11.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/twisted/24.3.0-1ubuntu0.2 https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.7 . Twisted's security flaw in Ubuntu could lead to a denial of service. Update to secure your system against potential crashes.. Ubuntu Security Update, Twisted Denial of Service, Critical Twisted Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Multiple security issues were found in Twisted, an event-based framework for internet applications, which could result in incorrect ordering of HTTP requests or cross-site scripting. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3970-1
Twisted could allow unintended access to information over the network.. ========================================================================== Ubuntu Security Notice USN-6988-2 November 26, 2024 twisted vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Twisted could allow unintended access to information over the network. Software Description: - twisted: Event-based framework for internet applications Details: USN-6988-1 fixed CVE-2024-41671 in Twisted. The USN incorrectly stated that previous releases were unaffected. This update provides the equivalent fix for Ubuntu 22.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 18.04 LTS. Original advisory details: Ben Kallus discovered that Twisted incorrectly handled response order when processing multiple HTTP requests. A remote attacker could possibly use this issue to delay and manipulate responses. This issue only affected Ubuntu 24.04 LTS. (CVE-2024-41671) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS python3-twisted 22.1.0-2ubuntu2.6 Ubuntu 20.04 LTS python3-twisted 18.9.0-11ubuntu0.20.04.5 Ubuntu 18.04 LTS python-twisted 17.9.0-2ubuntu0.3+esm2 Available with Ubuntu Pro python3-twisted 17.9.0-2ubuntu0.3+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6988-2 https://ubuntu.com/security/notices/USN-6988-1 CVE-2024-41671 PackageInformation: https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.6 https://launchpad.net/ubuntu/+source/twisted/18.9.0-11ubuntu0.20.04.5 . Utilizing Twisted in Ubuntu carries a potential danger of inadvertent data exposure across the network. Security patching recommended.. twisted, Ubuntu, information access, security advisory. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Twisted.. ========================================================================== Ubuntu Security Notice USN-6988-1 September 04, 2024 twisted vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Twisted. Software Description: - twisted: Event-based framework for internet applications Details: It was discovered that Twisted incorrectly handled response order when processing multiple HTTP requests. A remote attacker could possibly use this issue to delay and manipulate responses. This issue only affected Ubuntu 24.04 LTS. (CVE-2024-41671) It was discovered that Twisted did not properly sanitize certain input. An attacker could use this vulnerability to possibly execute an HTML injection leading to a cross-site scripting (XSS) attack. (CVE-2024-41810) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-twisted 24.3.0-1ubuntu0.1 Ubuntu 22.04 LTS python3-twisted 22.1.0-2ubuntu2.5 Ubuntu 20.04 LTS python3-twisted 18.9.0-11ubuntu0.20.04.4 Ubuntu 18.04 LTS python-twisted 17.9.0-2ubuntu0.3+esm1 Available with Ubuntu Pro python3-twisted 17.9.0-2ubuntu0.3+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS python-twisted 16.0.0-1ubuntu0.4+esm2 Available with Ubuntu Pro python3-twisted 16.0.0-1ubuntu0.4+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS python-twisted 13.2.0-1ubuntu1.2+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6988-1 CVE-2024-41671, CVE-2024-41810 Package Information: https://launchpad.net/ubuntu/+source/twisted/24.3.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.5 https://launchpad.net/ubuntu/+source/twisted/18.9.0-11ubuntu0.20.04.4 . Intricate security bulletin revisions for Ubuntu dealing with urgent risks and weaknesses recorded on October 02, 2024.. Ubuntu Updates, Twisted Framework, Security Threats, Cross-Site Scripting. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Twisted.. ========================================================================== Ubuntu Security Notice USN-6575-1 January 10, 2024 twisted vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Twisted. Software Description: - twisted: Event-based framework for internet applications Details: It was discovered that Twisted incorrectly escaped host headers in certain 404 responses. A remote attacker could possibly use this issue to perform HTML and script injection attacks. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-39348) It was discovered that Twisted incorrectly handled response order when processing multiple HTTP requests. A remote attacker could possibly use this issue to delay responses and manipulate the responses of second requests. (CVE-2023-46137) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: python3-twisted 22.4.0-4ubuntu0.23.10.1 Ubuntu 23.04: python3-twisted 22.4.0-4ubuntu0.23.04.1 Ubuntu 22.04 LTS: python3-twisted 22.1.0-2ubuntu2.4 Ubuntu 20.04 LTS: python3-twisted 18.9.0-11ubuntu0.20.04.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6575-1 CVE-2022-39348, CVE-2023-46137 Package Information: https://launchpad.net/ubuntu/+source/twisted/22.4.0-4ubuntu0.23.10.1 https://launchpad.net/ubuntu/+source/twisted/22.4.0-4ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/twisted/22.1.0-2ubuntu2.4 https://launchpad.net/ubuntu/+source/twisted/18.9.0-11ubuntu0.20.04.3 . Several securityissues fixed in Twisted for Ubuntu address critical HTML injection and response manipulation threats.. Twisted vulnerabilities, Ubuntu security, response manipulation. . Severity: Critical. LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in Twisted, the worst of which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202301-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Twisted: Multiple Vulnerabilities Date: January 11, 2023 Bugs: #878499, #834542, #832875 ID: 202301-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in Twisted, the worst of which could result in denial of service. Background ========= Twisted is an asynchronous networking framework written in Python. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-python/twisted < 22.10.0 > = 22.10.0 Description ========== Multiple vulnerabilities have been discovered in Twisted. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Twisted users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/twisted-22.10.0" References ========= [ 1 ] CVE-2022-21712 https://nvd.nist.gov/vuln/detail/CVE-2022-21712 [ 2 ] CVE-2022-21716 https://nvd.nist.gov/vuln/detail/CVE-2022-21716 [ 3 ] CVE-2022-39348 https://nvd.nist.gov/vuln/detail/CVE-2022-39348 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo SecurityWebsite: https://security.gentoo.org/glsa/202301-02 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
It was discovered that twisted, a framework for internet applications written in Python, was prone to an HTML injection when displaying the HTTP Host header in an error page. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3212-1
Get the latest Linux and open source security news straight to your inbox.