Technology · PyPI
twisted (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 16 vulnerabilities in twisted (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-41671, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 0
- Exploited in the wild
- 0
About twisted (PyPI)
Python networking engine supporting asynchronous event-driven programming with networking protocols.
Latest twisted (PyPI) vulnerabilities
- CVE-2024-41671: PYSEC-2026-1992 - twisted.web has disordered HTTP pipeline responselowCVSS 3.1EPSS 0.9%
- CVE-2022-39348: PYSEC-2026-1055 - Twisted vulnerable to NameVirtualHost Host header injectionlowCVSS 3.1EPSS 1.2%
- CVE-2026-42304: Twisted Denial of Service via DNS compression pointer chainshighCVSS 7.5EPSS 0.9%
- CVE-2024-41810: PYSEC-2024-75 - Twisted is an event-based framework for internet applications, supporting Python 3.6+. The…lowCVSS 3.1EPSS 1.2%
- CVE-2023-46137: PYSEC-2023-224 - Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending…lowCVSS 3.1EPSS 0.8%
- CVE-2022-24801: PYSEC-2022-195 - Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version…lowCVSS 3.1EPSS 2.8%
- CVE-2022-21716: PYSEC-2022-160 - Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0…lowCVSS 3.1EPSS 3.5%
- CVE-2022-21712: PYSEC-2022-27 - twisted is an event-driven networking engine written in Python. In affected versions twisted exposes…lowCVSS 3.1EPSS 1.4%
- CVE-2020-10108: PYSEC-2020-259 - In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with…lowCVSS 3.1EPSS 4.0%
- CVE-2020-10109: PYSEC-2020-260 - In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a…lowCVSS 3.1EPSS 3.3%
- CVE-2016-1000111: PYSEC-2020-214 - Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and…lowCVSS 3.1EPSS 2.8%
- CVE-2014-7143: PYSEC-2019-212 - Python Twisted 14.0 trustRoot is not respected in HTTP clientlowCVSS 3.1EPSS 2.6%
- CVE-2019-12855: PYSEC-2019-129 - In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates…lowCVSS 3EPSS 1.8%
- PYSEC-2019-59 - In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with…info
- PYSEC-2019-58 - In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an attacker to inject…info
- CVE-2019-12387: PYSEC-2019-128 - In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an…lowCVSS 3.1EPSS 2.5%
Most severe twisted (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-42304: Twisted Denial of Service via DNS compression pointer chainshighCVSS 7.5EPSS 0.9%
- CVE-2020-10108: PYSEC-2020-259 - In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with…lowCVSS 3.1EPSS 4.0%
- CVE-2022-21716: PYSEC-2022-160 - Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0…lowCVSS 3.1EPSS 3.5%
- CVE-2020-10109: PYSEC-2020-260 - In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a…lowCVSS 3.1EPSS 3.3%
- CVE-2022-24801: PYSEC-2022-195 - Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version…lowCVSS 3.1EPSS 2.8%
- CVE-2016-1000111: PYSEC-2020-214 - Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and…lowCVSS 3.1EPSS 2.8%
- CVE-2014-7143: PYSEC-2019-212 - Python Twisted 14.0 trustRoot is not respected in HTTP clientlowCVSS 3.1EPSS 2.6%
- CVE-2019-12387: PYSEC-2019-128 - In Twisted before 19.2.1, twisted.web did not validate or sanitize URIs or HTTP methods, allowing an…lowCVSS 3.1EPSS 2.5%
- CVE-2022-21712: PYSEC-2022-27 - twisted is an event-driven networking engine written in Python. In affected versions twisted exposes…lowCVSS 3.1EPSS 1.4%
- CVE-2022-39348: PYSEC-2026-1055 - Twisted vulnerable to NameVirtualHost Host header injectionlowCVSS 3.1EPSS 1.2%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/pypi-twisted.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "twisted (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/pypi-twisted, 28 September 2026.