Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-twisted | Aug 22, 2024 | Mar 3, 2022 |
| Amazon_linux | — | Upgrade python-twisted-conch | Jun 10, 2022 | Mar 3, 2022 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Mar 3, 2022 |
| Debian | — | Upgrade twisted | Mar 10, 2022 | Mar 3, 2022 |
| Gentoo Linux | — | Upgrade dev-python/twisted. | Jan 12, 2023 | Mar 3, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 3, 2022 |
| Suse | — | Upgrade python3-twistedUpgrade python2-twistedUpgrade python-twistedUpgrade python-twisted-doc | Oct 26, 2022 | Mar 3, 2022 |
| Ubuntu | — | Upgrade python-twisted (Ubuntu Pro)Upgrade python-twisted-bin (Ubuntu Pro)Upgrade python-twistedUpgrade python3-twistedUpgrade python-twisted-web (Ubuntu Pro)Upgrade python-twisted-binUpgrade python3-twisted-binUpgrade python3-twisted (Ubuntu Pro) | Mar 31, 2022 | Mar 3, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub