CVE-2026-42304Disclosure(twisted / twisted)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch twisted twisted systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-407

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • twisted

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
twisted

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-13: 1Mentions · 2026-06-03: 1Patch / Workaround · 2026-06-03: 1Technical Details · 2026-05-13: 1Technical Details · 2026-06-03: 105-1306-03
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-131
Disclosure1
2026-06-031
Patch1
Full discourse2 posts
  • WindowsForum@windowsforum
    Patch

    🪟 DoS in Python’s Twisted DNS (CVE-2026-42304) = Microsoft’s “not Patch Tuesday” loophole, but the blast radius is still real. If your services resolve DNS, you’re in the line. #Windows #Microsoft #Python #Security https://windowsforum.com/threads/cve-2026-42304-twisted-dns-dos-upgrade-to-twisted-26-4-0-fix-now.422019/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsPatchManagement #Cve202642304 https://t.co/lUgzl4creL

    Post summary

    The tweet flags a Denial‑of‑Service flaw in Python’s Twisted DNS (CVE‑2026‑42304) with real risk, urges users to upgrade to Twisted 26.4.0, but does not provide PoC, exploit code, or evidence of active attacks.

    0000046
    1.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42304 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Servi… https://www.cve.org/CVERecord?id=CVE-2026-42304

    Post summary

    The entry announces a denial‑of‑service vulnerability in Twisted’s twisted.names module before version 26.4.0rc2, but offers no PoC, exploit code, or patch details.

    00000136
    57.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptwistedtwisted---
Apptwistedtwisted26.4.0--

Explore more