Regular Expression Vulnerability in Twisted Framework for Python
CVE-2026-106454
4.3MEDIUM
What is CVE-2026-106454?
In Twisted Framework versions 25.5.0 and earlier, a flaw in the wildcardToRegexp function within the twisted/mail/imap4.py module leads to improper handling of LIST or LSUB patterns from authenticated clients. The function translates IMAP asterisk and percent wildcards but can pass unfiltered characters directly to re.compile(), allowing complex regular expressions to trigger catastrophic backtracking. This behavior results in significant performance degradation, as the single-threaded cooperative reactor of Twisted halts all server input and output during the regex match, potentially leading to service disruptions.
Affected Version(s)
twisted <= 25.5.0
