<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 06:24:15 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-42304</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-42304</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-twisted, Alpaquita:25: py3-twisted, Alpaquita:stream: py3-twisted&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: py3-twisted, Alpaquita:25: py3-twisted, Alpaquita:stream: py3-twisted&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-42304</guid>
    </item>
    <item>
      <title>BREW-alot-CVE-2026-42304 — Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains</title>
      <link>https://cve.radiocsirt.org/vuln/brew-alot-cve-2026-42304</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: alot&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Technical Details&lt;/p&gt;
&lt;p&gt;The main issue is in twisted.names.dns.Name.decode. A visited set was added in 2011 (commit e11cd82) to prevent infinite loops, but there is still no limit on the number of pointer dereferences per message. Also, the visited set is reset for each Question record.&lt;/p&gt;
&lt;p&gt;Because DNSServerFactory handles every record in QDCOUNT without checking them, an attacker can add thousands of questions that all refer to the same long chain of pointers. This makes the parser repeat a complex and unnecessary search.&lt;/p&gt;
&lt;p&gt;```python
##  src/twisted/names/dns.py (Lines 595-631)&lt;/p&gt;
&lt;p&gt;def decode(self, strio, length=None):
        visited = set()
        self.name = b&amp;#34;&amp;#34;
        off = 0
        while 1:
            l = ord(readPrecisely(strio, 1))
            if l == 0:
                if off &amp;gt; 0:
                    strio.seek(off)
                return
            if (l &amp;gt;&amp;gt; 6) == 3:
                new_off = (l &amp;amp; 63) &amp;lt;&amp;lt; 8 | ord(readPrecisely(strio, 1))
                if new_off in visited:
                    raise ValueErr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: alot&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Technical Details&lt;/p&gt;
&lt;p&gt;The main issue is in twisted.names.dns.Name.decode. A visited set was added in 2011 (commit e11cd82) to prevent infinite loops, but there is still no limit on the number of pointer dereferences per message. Also, the visited set is reset for each Question record.&lt;/p&gt;
&lt;p&gt;Because DNSServerFactory handles every record in QDCOUNT without checking them, an attacker can add thousands of questions that all refer to the same long chain of pointers. This makes the parser repeat a complex and unnecessary search.&lt;/p&gt;
&lt;p&gt;```python
##  src/twisted/names/dns.py (Lines 595-631)&lt;/p&gt;
&lt;p&gt;def decode(self, strio, length=None):
        visited = set()
        self.name = b&amp;#34;&amp;#34;
        off = 0
        while 1:
            l = ord(readPrecisely(strio, 1))
            if l == 0:
                if off &amp;gt; 0:
                    strio.seek(off)
                return
            if (l &amp;gt;&amp;gt; 6) == 3:
                new_off = (l &amp;amp; 63) &amp;lt;&amp;lt; 8 | ord(readPrecisely(strio, 1))
                if new_off in visited:
                    raise ValueErr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-alot-cve-2026-42304</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AF67526 — Security fixes for CVE-2026-42304, CVE-2026-44307, CVE-2026-48522, CVE-2026-48523, CVE-2026-48524, CVE-2026-48525, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-af67526</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jupyterhub-k8s-hub&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the jupyterhub-k8s-hub package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: jupyterhub-k8s-hub&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the jupyterhub-k8s-hub package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-af67526</guid>
    </item>
    <item>
      <title>EUVD-2026-318540</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-318540</link>
      <description>EUVD-2026-318540</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-318540</guid>
    </item>
    <item>
      <title>fkie_cve-2026-42304</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42304</link>
      <description>&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-42304</guid>
    </item>
    <item>
      <title>GHSA-grgv-6hw6-v9g4 — Twisted has a Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-grgv-6hw6-v9g4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Twisted&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Technical Details&lt;/p&gt;
&lt;p&gt;The main issue is in twisted.names.dns.Name.decode. A visited set was added in 2011 (commit e11cd82) to prevent infinite loops, but there is still no limit on the number of pointer dereferences per message. Also, the visited set is reset for each Question record.&lt;/p&gt;
&lt;p&gt;Because DNSServerFactory handles every record in QDCOUNT without checking them, an attacker can add thousands of questions that all refer to the same long chain of pointers. This makes the parser repeat a complex and unnecessary search.&lt;/p&gt;
&lt;p&gt;```python
##  src/twisted/names/dns.py (Lines 595-631)&lt;/p&gt;
&lt;p&gt;def decode(self, strio, length=None):
        visited = set()
        self.name = b&amp;#34;&amp;#34;
        off = 0
        while 1:
            l = ord(readPrecisely(strio, 1))
            if l == 0:
                if off &amp;gt; 0:
                    strio.seek(off)
                return
            if (l &amp;gt;&amp;gt; 6) == 3:
                new_off = (l &amp;amp; 63) &amp;lt;&amp;lt; 8 | ord(readPrecisely(strio, 1))
                if new_off in visited:
                    raise ValueErr…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Twisted&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;### Technical Details&lt;/p&gt;
&lt;p&gt;The main issue is in twisted.names.dns.Name.decode. A visited set was added in 2011 (commit e11cd82) to prevent infinite loops, but there is still no limit on the number of pointer dereferences per message. Also, the visited set is reset for each Question record.&lt;/p&gt;
&lt;p&gt;Because DNSServerFactory handles every record in QDCOUNT without checking them, an attacker can add thousands of questions that all refer to the same long chain of pointers. This makes the parser repeat a complex and unnecessary search.&lt;/p&gt;
&lt;p&gt;```python
##  src/twisted/names/dns.py (Lines 595-631)&lt;/p&gt;
&lt;p&gt;def decode(self, strio, length=None):
        visited = set()
        self.name = b&amp;#34;&amp;#34;
        off = 0
        while 1:
            l = ord(readPrecisely(strio, 1))
            if l == 0:
                if off &amp;gt; 0:
                    strio.seek(off)
                return
            if (l &amp;gt;&amp;gt; 6) == 3:
                new_off = (l &amp;amp; 63) &amp;lt;&amp;lt; 8 | ord(readPrecisely(strio, 1))
                if new_off in visited:
                    raise ValueErr…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-grgv-6hw6-v9g4</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-42304 — Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-42304</link>
      <description>msrc_CVE-2026-42304</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-42304</guid>
    </item>
    <item>
      <title>OESA-2026-2367 — python-twisted security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2367</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 2.7 and Python 3.5+. It includes modules for many different purposes, including the following:&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor&amp;amp;apos;s event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.(CVE-2026-42304)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: python-twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 2.7 and Python 3.5+. It includes modules for many different purposes, including the following:&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A denial of service vulnerability exists in Twisted framework when handling DNS compression pointer chains. A single malformed TCP packet is sufficient to block the Twisted reactor&amp;amp;apos;s event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this results in a common Denial of Service (DoS) attack. During this process, the server becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of decompression.(CVE-2026-42304)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2367</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10759-1 — python-Twisted-doc-26.4.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10759-1</link>
      <description>&lt;p&gt;python-Twisted-doc-26.4.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python-Twisted-doc-26.4.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10759-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-160</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-160</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-160</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22004-1 — Security update for python-Twisted</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22004-1</link>
      <description>&lt;p&gt;Security update for python-Twisted&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Twisted&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22004-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-42304</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42304</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: twisted, Ubuntu:Pro:16.04:LTS: twisted, Ubuntu:Pro:18.04:LTS: twisted, Ubuntu:20.04:LTS: twisted, Ubuntu:22.04:LTS: twisted, Ubuntu:24.04:LTS: twisted, Ubuntu:25.10: twisted, Ubuntu:26.04:LTS: twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: twisted, Ubuntu:Pro:16.04:LTS: twisted, Ubuntu:Pro:18.04:LTS: twisted, Ubuntu:20.04:LTS: twisted, Ubuntu:22.04:LTS: twisted, Ubuntu:24.04:LTS: twisted, Ubuntu:25.10: twisted, Ubuntu:26.04:LTS: twisted&lt;/p&gt;
&lt;p&gt;Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42304</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2455 — Oracle Solaris Drittanbieterkomponenten: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2455</link>
      <description>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in verschiedenen Komponenten von Drittanbietern in Oracle Solaris ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in verschiedenen Komponenten von Drittanbietern in Oracle Solaris ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2455</guid>
    </item>
  </channel>
</rss>
