Количество 9
Количество 9
CVE-2026-42304
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
CVE-2026-42304
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
CVE-2026-42304
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
CVE-2026-42304
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVE-2026-42304
Twisted is an event-based framework for internet applications, support ...
openSUSE-SU-2026:20862-1
Security update for python-Twisted
SUSE-SU-2026:2219-1
Security update for python-Twisted
SUSE-SU-2026:2218-1
Security update for python3-Twisted
GHSA-grgv-6hw6-v9g4
Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-42304 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42304 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42304 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42304 Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42304 Twisted is an event-based framework for internet applications, support ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20862-1 Security update for python-Twisted | 0% Низкий | 2 месяца назад | ||
SUSE-SU-2026:2219-1 Security update for python-Twisted | 0% Низкий | 2 месяца назад | ||
SUSE-SU-2026:2218-1 Security update for python3-Twisted | 0% Низкий | 2 месяца назад | ||
GHSA-grgv-6hw6-v9g4 Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу