Regular Expression Vulnerability in Twisted Framework for Python
CVE-2026-106454

4.3MEDIUM

Key Information:

Vendor

Twisted

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106454?

In Twisted Framework versions 25.5.0 and earlier, a flaw in the wildcardToRegexp function within the twisted/mail/imap4.py module leads to improper handling of LIST or LSUB patterns from authenticated clients. The function translates IMAP asterisk and percent wildcards but can pass unfiltered characters directly to re.compile(), allowing complex regular expressions to trigger catastrophic backtracking. This behavior results in significant performance degradation, as the single-threaded cooperative reactor of Twisted halts all server input and output during the regex match, potentially leading to service disruptions.

Affected Version(s)

twisted <= 25.5.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.