<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 03:41:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-04172</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-04172</link>
      <description>bdu:2025-04172</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-04172</guid>
    </item>
    <item>
      <title>BREW-alot-CVE-2024-41810 — Twisted vulnerable to HTML injection in HTTP redirect body</title>
      <link>https://cve.radiocsirt.org/vuln/brew-alot-cve-2024-41810</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: alot&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body.&lt;/p&gt;
&lt;p&gt;### Details
Twisted’s `redirectTo` function generates an `HTTP 302 Redirect` response. The response contains an HTML body, built for exceptional cases where the browser doesn’t properly handle the redirect, allowing the user to click a link, navigating them to the specified destination.&lt;/p&gt;
&lt;p&gt;The function reflects the destination URL in the HTML body without any output encoding. 
```python
# https://github.com/twisted/twisted/blob/trunk/src/twisted/web/_template_util.py#L88
def redirectTo(URL: bytes, request: IRequest) -&amp;gt; bytes:
    # ---snip---
    content = b&amp;#34;&amp;#34;&amp;#34;
&amp;lt;html&amp;gt;
    &amp;lt;head&amp;gt;
        &amp;lt;meta http-equiv=\&amp;#34;refresh\&amp;#34; content=\&amp;#34;0;URL=%(url)s\&amp;#34;&amp;gt;
    &amp;lt;/head&amp;gt;
    &amp;lt;body bgcolor=\&amp;#34;#FFFFFF\&amp;#34; text=\&amp;#34;#000000\&amp;#34;&amp;gt;
    &amp;lt;a href=\&amp;#34;%(url)s\&amp;#34;&amp;gt;click here&amp;lt;/a&amp;gt;
    &amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;
&amp;#34;&amp;#34;&amp;#34; % {
        b&amp;#34;url&amp;#34;: URL
    }
    return content
```&lt;/p&gt;
&lt;p&gt;If an attacker has full or partial control over redirect location due to an application bug, also known as an “Open Redirect”, they may inject arbitrary HTML into the response’s body, ultimately leading to an XSS attack.&lt;/p&gt;
&lt;p&gt;It’s worth noting that the issue is known to maintainers and tracked with GitHub [Issue#9839](https://github.com/twisted/twisted/issues/9839). The issue description, however, does…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: alot&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body.&lt;/p&gt;
&lt;p&gt;### Details
Twisted’s `redirectTo` function generates an `HTTP 302 Redirect` response. The response contains an HTML body, built for exceptional cases where the browser doesn’t properly handle the redirect, allowing the user to click a link, navigating them to the specified destination.&lt;/p&gt;
&lt;p&gt;The function reflects the destination URL in the HTML body without any output encoding. 
```python
# https://github.com/twisted/twisted/blob/trunk/src/twisted/web/_template_util.py#L88
def redirectTo(URL: bytes, request: IRequest) -&amp;gt; bytes:
    # ---snip---
    content = b&amp;#34;&amp;#34;&amp;#34;
&amp;lt;html&amp;gt;
    &amp;lt;head&amp;gt;
        &amp;lt;meta http-equiv=\&amp;#34;refresh\&amp;#34; content=\&amp;#34;0;URL=%(url)s\&amp;#34;&amp;gt;
    &amp;lt;/head&amp;gt;
    &amp;lt;body bgcolor=\&amp;#34;#FFFFFF\&amp;#34; text=\&amp;#34;#000000\&amp;#34;&amp;gt;
    &amp;lt;a href=\&amp;#34;%(url)s\&amp;#34;&amp;gt;click here&amp;lt;/a&amp;gt;
    &amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;
&amp;#34;&amp;#34;&amp;#34; % {
        b&amp;#34;url&amp;#34;: URL
    }
    return content
```&lt;/p&gt;
&lt;p&gt;If an attacker has full or partial control over redirect location due to an application bug, also known as an “Open Redirect”, they may inject arbitrary HTML into the response’s body, ultimately leading to an XSS attack.&lt;/p&gt;
&lt;p&gt;It’s worth noting that the issue is known to maintainers and tracked with GitHub [Issue#9839](https://github.com/twisted/twisted/issues/9839). The issue description, however, does…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-alot-cve-2024-41810</guid>
    </item>
    <item>
      <title>EUVD-2026-258653</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258653</link>
      <description>EUVD-2026-258653</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258653</guid>
    </item>
    <item>
      <title>fkie_cve-2024-41810</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-41810</link>
      <description>&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-41810</guid>
    </item>
    <item>
      <title>GHSA-cf56-g6w6-pqq2 — Twisted vulnerable to HTML injection in HTTP redirect body</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-cf56-g6w6-pqq2</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: twisted&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body.&lt;/p&gt;
&lt;p&gt;### Details
Twisted’s `redirectTo` function generates an `HTTP 302 Redirect` response. The response contains an HTML body, built for exceptional cases where the browser doesn’t properly handle the redirect, allowing the user to click a link, navigating them to the specified destination.&lt;/p&gt;
&lt;p&gt;The function reflects the destination URL in the HTML body without any output encoding. 
```python
# https://github.com/twisted/twisted/blob/trunk/src/twisted/web/_template_util.py#L88
def redirectTo(URL: bytes, request: IRequest) -&amp;gt; bytes:
    # ---snip---
    content = b&amp;#34;&amp;#34;&amp;#34;
&amp;lt;html&amp;gt;
    &amp;lt;head&amp;gt;
        &amp;lt;meta http-equiv=\&amp;#34;refresh\&amp;#34; content=\&amp;#34;0;URL=%(url)s\&amp;#34;&amp;gt;
    &amp;lt;/head&amp;gt;
    &amp;lt;body bgcolor=\&amp;#34;#FFFFFF\&amp;#34; text=\&amp;#34;#000000\&amp;#34;&amp;gt;
    &amp;lt;a href=\&amp;#34;%(url)s\&amp;#34;&amp;gt;click here&amp;lt;/a&amp;gt;
    &amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;
&amp;#34;&amp;#34;&amp;#34; % {
        b&amp;#34;url&amp;#34;: URL
    }
    return content
```&lt;/p&gt;
&lt;p&gt;If an attacker has full or partial control over redirect location due to an application bug, also known as an “Open Redirect”, they may inject arbitrary HTML into the response’s body, ultimately leading to an XSS attack.&lt;/p&gt;
&lt;p&gt;It’s worth noting that the issue is known to maintainers and tracked with GitHub [Issue#9839](https://github.com/twisted/twisted/issues/9839). The issue description, however, does…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: twisted&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body.&lt;/p&gt;
&lt;p&gt;### Details
Twisted’s `redirectTo` function generates an `HTTP 302 Redirect` response. The response contains an HTML body, built for exceptional cases where the browser doesn’t properly handle the redirect, allowing the user to click a link, navigating them to the specified destination.&lt;/p&gt;
&lt;p&gt;The function reflects the destination URL in the HTML body without any output encoding. 
```python
# https://github.com/twisted/twisted/blob/trunk/src/twisted/web/_template_util.py#L88
def redirectTo(URL: bytes, request: IRequest) -&amp;gt; bytes:
    # ---snip---
    content = b&amp;#34;&amp;#34;&amp;#34;
&amp;lt;html&amp;gt;
    &amp;lt;head&amp;gt;
        &amp;lt;meta http-equiv=\&amp;#34;refresh\&amp;#34; content=\&amp;#34;0;URL=%(url)s\&amp;#34;&amp;gt;
    &amp;lt;/head&amp;gt;
    &amp;lt;body bgcolor=\&amp;#34;#FFFFFF\&amp;#34; text=\&amp;#34;#000000\&amp;#34;&amp;gt;
    &amp;lt;a href=\&amp;#34;%(url)s\&amp;#34;&amp;gt;click here&amp;lt;/a&amp;gt;
    &amp;lt;/body&amp;gt;
&amp;lt;/html&amp;gt;
&amp;#34;&amp;#34;&amp;#34; % {
        b&amp;#34;url&amp;#34;: URL
    }
    return content
```&lt;/p&gt;
&lt;p&gt;If an attacker has full or partial control over redirect location due to an application bug, also known as an “Open Redirect”, they may inject arbitrary HTML into the response’s body, ultimately leading to an XSS attack.&lt;/p&gt;
&lt;p&gt;It’s worth noting that the issue is known to maintainers and tracked with GitHub [Issue#9839](https://github.com/twisted/twisted/issues/9839). The issue description, however, does…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-cf56-g6w6-pqq2</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-41810 — HTML injection in HTTP redirect body</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-41810</link>
      <description>msrc_CVE-2024-41810</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-41810</guid>
    </item>
    <item>
      <title>OESA-2024-1983 — python-twisted security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1983</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 2.7 and Python 3.5+. It includes modules for many different purposes, including the following:&#13;
&#13;
Security Fix(es):&#13;
&#13;
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.(CVE-2024-41671)&#13;
&#13;
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.(CVE-2024-41810)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 2.7 and Python 3.5+. It includes modules for many different purposes, including the following:&#13;
&#13;
Security Fix(es):&#13;
&#13;
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.(CVE-2024-41671)&#13;
&#13;
Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.(CVE-2024-41810)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1983</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14236-1 — python-Twisted-doc-24.3.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14236-1</link>
      <description>&lt;p&gt;python-Twisted-doc-24.3.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-Twisted-doc-24.3.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14236-1</guid>
    </item>
    <item>
      <title>PYSEC-2024-75</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2024-75</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2024-75</guid>
    </item>
    <item>
      <title>RHSA-2024:7312 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.4 Product Security and Bug Fix Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2024:7312</link>
      <description>&lt;p&gt;djangorestframework: Cross-site Scripting (XSS) via break_long_headers urllib3: proxy-authorization request header is not stripped during cross-origin redirects python-twisted: Reflected XSS via HTML Injection in Redirect Response&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;djangorestframework: Cross-site Scripting (XSS) via break_long_headers urllib3: proxy-authorization request header is not stripped during cross-origin redirects python-twisted: Reflected XSS via HTML Injection in Redirect Response&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2024:7312</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:2732-1 — Security update for python-Twisted</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:2732-1</link>
      <description>&lt;p&gt;Security update for python-Twisted&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Twisted&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:2732-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-41810</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-41810</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: twisted, Ubuntu:Pro:16.04:LTS: twisted, Ubuntu:Pro:18.04:LTS: twisted, Ubuntu:20.04:LTS: twisted, Ubuntu:22.04:LTS: twisted, Ubuntu:24.04:LTS: twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: twisted, Ubuntu:Pro:16.04:LTS: twisted, Ubuntu:Pro:18.04:LTS: twisted, Ubuntu:20.04:LTS: twisted, Ubuntu:22.04:LTS: twisted, Ubuntu:24.04:LTS: twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. The `twisted.web.util.redirectTo` function contains an HTML injection vulnerability. If application code allows an attacker to control the redirect URL this vulnerability may result in Reflected Cross-Site Scripting (XSS) in the redirect response HTML body. This vulnerability is fixed in 24.7.0rc1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-41810</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-2229 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2229</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen oder vertrauliche Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-2229</guid>
    </item>
  </channel>
</rss>
