© 2025-2026 PySpect
First version without a known vulnerability: 26.4.0
Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Fixed in: 26.4.0rc2, 26.4.0
Twisted vulnerable to HTML injection in HTTP redirect body
Fixed in: 24.7.0rc1, 046a164f89a0f08d3239ecebd750360f8914df33
twisted.web has disordered HTTP pipeline response
Fixed in: 24.7.0rc1
twisted.web has disordered HTTP pipeline response
Fixed in: 23.10.0rc1
Twisted vulnerable to NameVirtualHost Host header injection
Fixed in: 22.10.0rc1
Twisted vulnerable to HTTP Request Smuggling Attacks
Fixed in: 20.3.0
Inconsistent Interpretation of HTTP Requests in twisted.web
Fixed in: 22.4.0, 592217e951363d60e9cd99c5bbfd23d4615043ac
HTTP/2 DoS Attacks: Ping, Reset, and Settings Floods
Fixed in: 19.10.0
Twisted SSH client and server deny of service during SSH handshake.
Fixed in: 22.2.0, 89c395ee794e85a9657b112c4351417850330ef9
Cookie and header exposure in twisted
Fixed in: 22.1.0, af8fe78542a6f2bf2235ccee8158d9c88d31e8e2
Forced Browsing in Twisted
Fixed in: 16.3.1
Improper Input Validation in Twisted
Fixed in: 20.3.0, 20.3.0rc1
HTTP Request Smuggling in Twisted
Fixed in: 20.3.0, 20.3.0rc1
Python Twisted trustRoot is not respected in HTTP client
Fixed in: 14.0.1
Improper Certificate Validation in Twisted
Fixed in: 19.7.0rc1
Twisted CRLF Injection
Fixed in: 19.2.1, 6c61fc4503ae39ab8ecee52d10f10ee2c371d7e2