Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3970-1 | twisted security update |
Debian DSA |
DSA-5797-1 | twisted security update |
EUVD |
EUVD-2023-0250 | Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue. |
Github GHSA |
GHSA-xc8x-vp79-p3wm | twisted.web has disordered HTTP pipeline response |
Ubuntu USN |
USN-6575-1 | Twisted vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 25 Nov 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Twisted
Twisted twisted |
|
| CPEs | cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Twistedmatrix
Twistedmatrix twisted |
Twisted
Twisted twisted |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T21:49:56.068Z
Reserved: 2023-10-16T17:51:35.574Z
Link: CVE-2023-46137
Updated: 2024-08-02T20:37:39.805Z
Status : Modified
Published: 2023-10-25T21:15:10.237
Modified: 2025-11-03T22:16:28.480
Link: CVE-2023-46137
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN