Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.
CVSS Details
- CVSS 3.1 Base Score: 8.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-synapse | Aug 22, 2024 | Jul 29, 2024 | |
| Debian | debian-upgrade-twisted | Oct 28, 2024 | Jul 29, 2024 | |
| Dell Powerstore Dsa2025086 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Feb 20, 2025 | |
| Suse | — | suse-upgrade-python-twistedsuse-upgrade-python-twisted-docsuse-upgrade-python3-twistedsuse-upgrade-python311-twistedsuse-upgrade-python311-twisted-all_non_platformsuse-upgrade-python311-twisted-conchsuse-upgrade-python311-twisted-conch_naclsuse-upgrade-python311-twisted-contextvarssuse-upgrade-python311-twisted-http2suse-upgrade-python311-twisted-serialsuse-upgrade-python311-twisted-tlssuse-upgrade-python313-twistedsuse-upgrade-python313-twisted-all_non_platformsuse-upgrade-python313-twisted-conchsuse-upgrade-python313-twisted-conch_naclsuse-upgrade-python313-twisted-contextvarssuse-upgrade-python313-twisted-http2suse-upgrade-python313-twisted-serialsuse-upgrade-python313-twisted-tls | Aug 6, 2024 | Jul 29, 2024 |
| Ubuntu | ubuntu-pro-upgrade-python-twistedubuntu-pro-upgrade-python3-twistedubuntu-upgrade-python3-twisted | Sep 5, 2024 | Jul 29, 2024 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Feb 9, 2026 | Jul 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub