Search CVE reports


Toggle filters

1 – 10 of 16 results


CVE-2024-41810

Medium priority
Fixed

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the...

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-41671

Medium priority
Fixed

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information...

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Fixed Fixed Fixed Fixed
Show less packages

CVE-2023-46137

Medium priority

Some fixes available 7 of 10

Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the...

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2022-39348

Low priority

Some fixes available 2 of 6

Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders...

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2022-24801

Medium priority

Some fixes available 7 of 12

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs...

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Fixed Fixed Ignored Ignored
Show less packages

CVE-2022-21716

Medium priority
Fixed

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier....

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Fixed Fixed Fixed
Show less packages

CVE-2022-21712

Medium priority

Some fixes available 10 of 12

twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent`...

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Fixed Fixed Fixed Fixed
Show less packages

CVE-2020-10109

Medium priority
Fixed

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was...

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Fixed
Show less packages

CVE-2020-10108

Medium priority
Fixed

In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body...

1 affected package

twisted

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
twisted Fixed
Show less packages

CVE-2019-9515

Medium priority

Some fixes available 15 of 63

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with...

7 affected packages

golang-google-grpc, grpc, h2o, nginx, trafficserver...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-google-grpc Vulnerable Vulnerable Vulnerable Vulnerable
grpc Vulnerable Vulnerable Vulnerable Vulnerable
h2o Not affected Not affected Not affected Vulnerable
nginx Not affected Not affected Not affected Not affected
trafficserver Not affected Not affected Not affected Vulnerable
twisted Fixed Fixed Fixed Fixed
netty Not affected Not affected Not affected Fixed
Show all 7 packages Show less packages