twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-py3-twisted | Aug 22, 2024 | Feb 7, 2022 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Feb 7, 2022 | |
| Debian | debian-upgrade-twisted | Feb 23, 2022 | Feb 7, 2022 | |
| Dell Powerstore Dsa2023173 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Jun 21, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-python-twisted | Jan 12, 2023 | Feb 7, 2022 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Feb 7, 2022 |
| Suse | — | suse-upgrade-python-twistedsuse-upgrade-python-twisted-docsuse-upgrade-python2-twistedsuse-upgrade-python3-twisted | Feb 19, 2022 | Feb 7, 2022 |
| Ubuntu | ubuntu-upgrade-python-twistedubuntu-upgrade-python-twisted-binubuntu-upgrade-python3-twistedubuntu-upgrade-python3-twisted-bin | Mar 31, 2022 | Feb 7, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub