Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42304

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 7.5

Описание

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.

A flaw was found in Twisted, specifically within the twisted.names module. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted TCP DNS packet containing deeply chained compression pointers. This can lead to resource exhaustion, causing the single-threaded Twisted reactor to hang and effectively freezing the server, resulting in a Denial of Service (DoS).

Отчет

A flaw was found in the twisted.names DNS module of the Python Twisted framework. A remote unauthenticated attacker can send a single crafted TCP DNS packet containing deeply chained compression pointers and thousands of question records to hang the single-threaded Twisted reactor, effectively freezing the server. The visited set that prevents infinite loops has no limit on total pointer dereferences and is reset per question record, allowing resource exhaustion. Red Hat Ansible Automation Platform components (automation-controller, EDA controller, Lightspeed) bundle python-twisted but use it via Daphne as an ASGI server. These components do not import or execute twisted.names, so the vulnerable DNS decompression code is never reached. Red Hat Enterprise Linux 6 ships python-twisted but is out of support scope (ELS does not cover python-twisted).

Меры по смягчению последствий

There is no mitigation for this issue. Applications using twisted.names for DNS resolution or as a DNS server should update to a fixed version of Twisted when available. Upgrade to a patched version (>= 26.4.0rc2).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/controller-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/eda-controller-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9Not affected
Red Hat Ansible Automation Platform 2automation-controllerNot affected
Red Hat Ansible Automation Platform 2python-twistedNot affected
Red Hat Enterprise Linux 6python-twistedOut of support scope
Red Hat Hardened Imagespython-jsonschemaNot affected
Red Hat OpenStack Platform 16.2python-twistedNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2477296python-twisted: Twisted: Denial of Service via crafted DNS packets in twisted.names

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.

CVSS3: 7.5
nvd
3 месяца назад

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.

CVSS3: 7.5
msrc
3 месяца назад

Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains

CVSS3: 7.5
debian
3 месяца назад

Twisted is an event-based framework for internet applications, support ...

suse-cvrf
2 месяца назад

Security update for python-Twisted

7.5 High

CVSS3