twisted records
14 published records for vendor twisted.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')5
- CWE-295 Improper Certificate Validation2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-425 Direct Request ('Forced Browsing')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-10108No exploit | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Critical9.8 | — | 4.0% | Mar 12, 2020 |
40Plan | CVE-2020-10109No exploit | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.twisted · twisted · CWE-444 | Critical9.8 | — | 3.3% | Mar 12, 2020 |
33Monitor | CVE-2022-24801No exploit | HTTP Request Smuggling in twisted.webtwisted · twisted · CWE-444 | High8.1 | — | 2.8% | Apr 4, 2022 |
33Monitor | CVE-2024-41671No exploit | twisted.web has disordered HTTP pipeline responsetwisted · twisted · CWE-444 | High8.3 | — | 0.9% | Jul 29, 2024 |
31Monitor | CVE-2022-21716No exploit | Buffer Overflow in Twistedtwisted · twisted · CWE-120 | High7.5 | — | 3.5% | Mar 3, 2022 |
31Monitor | CVE-2014-7143No exploit | Python Twisted 14.0 trustRoot is not respected in HTTP clienttwisted · twisted · CWE-295 | High7.5 | — | 2.6% | Nov 12, 2019 |
30Monitor | CVE-2019-12855No exploit | In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attatwisted · twisted · CWE-295 | High7.4 | — | 1.8% | Jun 16, 2019 |
30Monitor | CVE-2022-21712No exploit | Cookie and header exposure in twistedtwisted · twisted · CWE-200 | High7.5 | — | 1.4% | Feb 7, 2022 |
30Monitor | CVE-2026-42304No exploit | Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chainstwisted · twisted · CWE-400 | High7.5 | — | 1.0% | May 13, 2026 |
25Monitor | CVE-2019-12387No exploit | In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters stwisted · twisted · CWE-74 | Medium6.1 | — | 2.5% | Jun 10, 2019 |
24Monitor | CVE-2024-41810Proof of concept | HTML injection in HTTP redirect bodytwisted · twisted · CWE-79 | Medium6.1 | — | 1.2% | Jul 29, 2024 |
22Monitor | CVE-2016-1000111No exploit | Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applicationtwisted · twisted · CWE-425 | Medium5.3 | — | 2.8% | Mar 11, 2020 |
21Monitor | CVE-2022-39348No exploit | Twisted vulnerable to NameVirtualHost Host header injectiontwisted · twisted · CWE-79 | Medium5.4 | — | 1.2% | Oct 26, 2022 |
21Monitor | CVE-2023-46137No exploit | twisted.web has disordered HTTP pipeline responsetwisted · twisted · CWE-444 | Medium5.3 | — | 0.8% | Oct 25, 2023 |
- CVE-2020-1010840Plan
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
CriticalCVSS 9.8No exploitEPSS 4%twisted · twistedMar 12, 2020
- CVE-2020-1010940Plan
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability.
CriticalCVSS 9.8No exploitEPSS 3%twisted · twistedMar 12, 2020
- CVE-2022-2480133Monitor
HTTP Request Smuggling in twisted.web
HighCVSS 8.1No exploitEPSS 3%twisted · twistedApr 4, 2022
- CVE-2024-4167133Monitor
twisted.web has disordered HTTP pipeline response
HighCVSS 8.3No exploitEPSS 1%twisted · twistedJul 29, 2024
- CVE-2022-2171631Monitor
Buffer Overflow in Twisted
HighCVSS 7.5No exploitEPSS 4%twisted · twistedMar 3, 2022
- CVE-2014-714331Monitor
Python Twisted 14.0 trustRoot is not respected in HTTP client
HighCVSS 7.5No exploitEPSS 3%twisted · twistedNov 12, 2019
- CVE-2019-1285530Monitor
In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an atta
HighCVSS 7.4No exploitEPSS 2%twisted · twistedJun 16, 2019
- CVE-2022-2171230Monitor
Cookie and header exposure in twisted
HighCVSS 7.5No exploitEPSS 1%twisted · twistedFeb 7, 2022
- CVE-2026-4230430Monitor
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
HighCVSS 7.5No exploitEPSS 1%twisted · twistedMay 13, 2026
- CVE-2019-1238725Monitor
In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject invalid characters s
MediumCVSS 6.1No exploitEPSS 3%twisted · twistedJun 10, 2019
- CVE-2024-4181024Monitor
HTML injection in HTTP redirect body
MediumCVSS 6.1Proof of conceptEPSS 1%twisted · twistedJul 29, 2024
- CVE-2016-100011122Monitor
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI application
MediumCVSS 5.3No exploitEPSS 3%twisted · twistedMar 11, 2020
- CVE-2022-3934821Monitor
Twisted vulnerable to NameVirtualHost Host header injection
MediumCVSS 5.4No exploitEPSS 1%twisted · twistedOct 26, 2022
- CVE-2023-4613721Monitor
twisted.web has disordered HTTP pipeline response
MediumCVSS 5.3No exploitEPSS 1%twisted · twistedOct 25, 2023