twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-twisted | Aug 22, 2024 | Feb 7, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 7, 2022 |
| Debian | — | Upgrade twisted | Feb 23, 2022 | Feb 7, 2022 |
| Dell Powerstore Dsa2023173 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jun 21, 2023 |
| Gentoo Linux | — | Upgrade dev-python/twisted. | Jan 12, 2023 | Feb 7, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 7, 2022 |
| Suse | — | Upgrade python3-twistedUpgrade python-twistedUpgrade python2-twistedUpgrade python-twisted-doc | Feb 19, 2022 | Feb 7, 2022 |
| Ubuntu | — | Upgrade python3-twistedUpgrade python-twisted-binUpgrade python-twistedUpgrade python3-twisted-bin | Mar 31, 2022 | Feb 7, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub