Impact
A vulnerability exists in the Twisted event‑based framework where the wildcardToRegexp() function in twisted/mail/imap4.py passes unfiltered user input from IMAP LIST or LSUB commands to Python’s re.compile() without sanitizing pattern characters beyond the asterisk and percent wildcards. This opens the possibility of catastro‑phic backtracking when a malicious pattern is matched against mailbox names. Because Twisted runs a single‑threaded reactor, the blocking regex match suspends all server input and output for the duration of the match, effectively causing a denial of service. The weakness is a regular expression denial‑of‑service (CWE‑1333).
Affected Systems
Twisted, the Python event‑based framework for internet applications, is affected on versions 25.5.0 and earlier. The issue is relevant for Python 3.6 and newer.
Risk and Exploitability
The CVSS score is 4.3, indicating a low to medium severity impact. An attacker must be authenticated to issue a LIST or LSUB command that includes a malicious pattern, so the attack is limited to users who have logged into the IMAP service. Exhaustive backtracking can suspend the reactor and block all connections, causing service outages. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a relatively low likelihood of widespread exploitation at present. However, the flaw’s easier exploitation – just sending a crafted pattern – means that any user with authenticated access could trigger the DoS, so it is advisable to mitigate or monitor until a vendor patch is released.
OpenCVE Enrichment