PT-2026-107243 · Twisted · Twisted

CVE-2026-106454

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Twisted versions 25.5.0 and earlier
Description The wildcardToRegexp() function in twisted/mail/imap4.py improperly handles patterns from authenticated clients during LIST or LSUB operations. While it translates IMAP asterisk and percent wildcards, it passes all other characters directly to re.compile(). This allows the use of nested or expensive regular expression constructs that can trigger catastrophic backtracking—a state where the regex engine takes an exponential amount of time to determine that a string does not match a pattern—when matched against mailbox names. Since Twisted utilizes a cooperative single-threaded reactor, this blocking operation suspends all server input and output for the duration of the match.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106454
GHSA-8PQF-F4M5-798G

Affected Products

Twisted