Description
Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and earlier, wildcardToRegexp() in twisted/mail/imap4.py translates the IMAP asterisk and percent wildcards but passes all other characters from an authenticated client's LIST or LSUB pattern directly to re.compile(), allowing nested or otherwise expensive regular expression constructs to cause catastrophic backtracking when matched against mailbox names. Because Twisted uses a cooperative single-threaded reactor, the blocking match suspends all server input and output for the duration of the match. No fixed release is available as of this review.
Published: 2026-10-06
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Monitor
AI Analysis

Impact

A vulnerability exists in the Twisted event‑based framework where the wildcardToRegexp() function in twisted/mail/imap4.py passes unfiltered user input from IMAP LIST or LSUB commands to Python’s re.compile() without sanitizing pattern characters beyond the asterisk and percent wildcards. This opens the possibility of catastro‑phic backtracking when a malicious pattern is matched against mailbox names. Because Twisted runs a single‑threaded reactor, the blocking regex match suspends all server input and output for the duration of the match, effectively causing a denial of service. The weakness is a regular expression denial‑of‑service (CWE‑1333).

Affected Systems

Twisted, the Python event‑based framework for internet applications, is affected on versions 25.5.0 and earlier. The issue is relevant for Python 3.6 and newer.

Risk and Exploitability

The CVSS score is 4.3, indicating a low to medium severity impact. An attacker must be authenticated to issue a LIST or LSUB command that includes a malicious pattern, so the attack is limited to users who have logged into the IMAP service. Exhaustive backtracking can suspend the reactor and block all connections, causing service outages. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a relatively low likelihood of widespread exploitation at present. However, the flaw’s easier exploitation – just sending a crafted pattern – means that any user with authenticated access could trigger the DoS, so it is advisable to mitigate or monitor until a vendor patch is released.

Generated by OpenCVE AI on October 7, 2026 at 00:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict or disable the IMAP LIST and LSUB commands for authenticated users until a vendor fix is available, reducing exposure to the dangerous input.
  • Implement an additional input‑validation layer that rejects or limits patterns containing nested quantifiers or other constructs that can trigger catastrophic backtracking before they reach re.compile().
  • Continuously monitor the Twisted project for updates and apply any released patch or upgrade to a newer, unaffected version as soon as it becomes available.

Generated by OpenCVE AI on October 7, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Twisted
Twisted twisted
Vendors & Products Twisted
Twisted twisted

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and earlier, wildcardToRegexp() in twisted/mail/imap4.py translates the IMAP asterisk and percent wildcards but passes all other characters from an authenticated client's LIST or LSUB pattern directly to re.compile(), allowing nested or otherwise expensive regular expression constructs to cause catastrophic backtracking when matched against mailbox names. Because Twisted uses a cooperative single-threaded reactor, the blocking match suspends all server input and output for the duration of the match. No fixed release is available as of this review.
Title Twisted: IMAP wildcardToRegexp() ReDoS
Weaknesses CWE-1333
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:55:36.523Z

Reserved: 2026-10-06T16:49:40.591Z

Link: CVE-2026-106454

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:27.597

Modified: 2026-10-06T20:17:27.597

Link: CVE-2026-106454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:00:09Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity