Vulnerability PYSEC-2026-160

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 months ago
May 13, 2026 at 09:16 PM UTC
No summary available
1.0.1 - 26.4.0rc2
1.0.1 - 26.4.0rc2

Details

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.

Impacted packages

Timeline

Published
4 months ago
May 13, 2026 at 09:16 PM UTC
Fixed (26.4.0)
4 months ago
May 11, 2026 at 11:24 AM UTC
Last Modified
4 months ago
May 20, 2026 at 12:35 PM UTC