Vulnerability PYSEC-2026-1055

Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
July 07, 2026 at 10:17 AM UTC
Twisted vulnerable to NameVirtualHost Host header injection
1.0.1 - 22.8.0
1.0.1 - 22.8.0

Summary

Twisted vulnerable to NameVirtualHost Host header injection

Details

When the host header does not match a configured host, twisted.web.vhost.NameVirtualHost will return a NoResource resource which renders the Host header unescaped into the 404 response allowing HTML and script injection.

Example configuration:

from twisted.web.server import Site
from twisted.web.vhost import NameVirtualHost
from twisted.internet import reactor

resource = NameVirtualHost()
site = Site(resource)
reactor.listenTCP(8080, site)
reactor.run()

Output:

❯ curl -H"Host:<h1>HELLO THERE</h1>" http://localhost:8080/

<html>
  <head><title>404 - No Such Resource</title></head>
  <body>
    <h1>No Such Resource</h1>
    <p>host b'<h1>hello there</h1>' not in vhost map</p>
  </body>
</html>

This vulnerability was introduced in f49041bb67792506d85aeda9cf6157e92f8048f4 and first appeared in the 0.9.4 release.

Impacted packages

Timeline

Published
3 months ago
July 07, 2026 at 10:17 AM UTC
Fixed (22.10.0rc1)
3 years ago
October 26, 2022 at 07:19 PM UTC
Last Modified
3 months ago
July 07, 2026 at 11:46 AM UTC