CVE-2022-24801
published 2022-04-04CVE-2022-24801: Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in…
PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.80%
84.9th percentile
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ensure any vulnerabilities in upstream proxies have been addressed, such as by upgrading them; or filter malformed requests by other means, such as configuration of an upstream proxy.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | twisted | < twisted 22.4.0-1 (bookworm) | twisted 22.4.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_python-twisted_22.10.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_python-twisted_20.3.0-3_on_cbl_mariner_1.0 | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| twisted | twisted | < 22.4.0 | 22.4.0 |
| twisted | twisted | <= 22.2.0 | — |
| twisted | twisted | >= 0 < 20.3.0-7+deb11u1 | 20.3.0-7+deb11u1 |
| twisted | twisted | >= 0 < 22.4.0-1 | 22.4.0-1 |
| twisted | twisted | >= 0 < 22.4.0-1 | 22.4.0-1 |
| twisted | twisted | >= 0 < 22.4.0-1 | 22.4.0-1 |
| twisted | twisted | >= 0 < 22.4.0 | 22.4.0 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_msrc8.1HIGH
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Twisted vulnerability
vendor_ubuntu·2022-08-24
CVE-2022-24801 Twisted vulnerability
Title: Twisted vulnerability
Summary: Twisted could be made to expose sensitive information over the
network.
It was discovered that Twisted incorrectly parsed some types of HTTP requests
in its web server implementation. In certain proxy or multi-server
configurations, a remote attacker could craft malicious HTTP requests in order
to obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Systems Risk Matrix: Operating System Image — CVE-2022-24801
vendor_oracle·2022-07-15·CVSS 8.1
CVE-2022-24801 [HIGH] Oracle Oracle Systems Risk Matrix: Operating System Image — CVE-2022-24801
Oracle Oracle Systems Risk Matrix: Operating System Image vulnerability
CVE: CVE-2022-24801
CVSS: 8.1
Protocol: Multiple
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Microsoft
HTTP Request Smuggling in twisted.web
vendor_msrc·2022-04-12·CVSS 8.1
CVE-2022-24801 [HIGH] CWE-444 HTTP Request Smuggling in twisted.web
HTTP Request Smuggling in twisted.web
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.c
Red Hat
python-twisted: possible http request smuggling
vendor_redhat·2022-04-04·CVSS 8.1
CVE-2022-24801 [HIGH] CWE-444 python-twisted: possible http request smuggling
python-twisted: possible http request smuggling
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ens
Debian
CVE-2022-24801: twisted - Twisted is an event-based framework for internet applications, supporting Python...
vendor_debian·2022·CVSS 8.1
CVE-2022-24801 [HIGH] CVE-2022-24801: twisted - Twisted is an event-based framework for internet applications, supporting Python...
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ensure any vulnerabilities in upstream proxies have
OSV
CVE-2022-24801: Twisted is an event-based framework for internet applications, supporting Python 3
osv·2022-04-04·CVSS 8.1
CVE-2022-24801 [HIGH] CVE-2022-24801: Twisted is an event-based framework for internet applications, supporting Python 3
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ensure any vulnerabilities in upstream proxies have
OSV
Inconsistent Interpretation of HTTP Requests in twisted.web
osv·2022-04-04
CVE-2022-24801 [CRITICAL] Inconsistent Interpretation of HTTP Requests in twisted.web
Inconsistent Interpretation of HTTP Requests in twisted.web
The Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230:
1. The Content-Length header value could have a `+` or `-` prefix.
2. Illegal characters were permitted in chunked extensions, such as the LF (`\n`) character.
3. Chunk lengths, which are expressed in hexadecimal format, could have a prefix of `0x`.
4. HTTP headers were stripped of all leading and trailing ASCII whitespace, rather than only space and HTAB (`\t`).
This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling.
### Impact
You may be affected if:
1. You use Twisted Web's HTTP 1.
GHSA
Inconsistent Interpretation of HTTP Requests in twisted.web
ghsa·2022-04-04
CVE-2022-24801 [CRITICAL] CWE-444 Inconsistent Interpretation of HTTP Requests in twisted.web
Inconsistent Interpretation of HTTP Requests in twisted.web
The Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230:
1. The Content-Length header value could have a `+` or `-` prefix.
2. Illegal characters were permitted in chunked extensions, such as the LF (`\n`) character.
3. Chunk lengths, which are expressed in hexadecimal format, could have a prefix of `0x`.
4. HTTP headers were stripped of all leading and trailing ASCII whitespace, rather than only space and HTAB (`\t`).
This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling.
### Impact
You may be affected if:
1. You use Twisted Web's HTTP 1.
No detection rules found.
No public exploits indexed.
https://github.com/twisted/twisted/commit/592217e951363d60e9cd99c5bbfd23d4615043achttps://github.com/twisted/twisted/releases/tag/twisted-22.4.0rc1https://github.com/twisted/twisted/security/advisories/GHSA-c2jg-hw38-jrqqhttps://lists.debian.org/debian-lts-announce/2022/05/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6/https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://github.com/twisted/twisted/commit/592217e951363d60e9cd99c5bbfd23d4615043achttps://github.com/twisted/twisted/releases/tag/twisted-22.4.0rc1https://github.com/twisted/twisted/security/advisories/GHSA-c2jg-hw38-jrqqhttps://lists.debian.org/debian-lts-announce/2022/05/msg00003.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7U6KYDTOLPICAVSR34G2WRYLFBD2YW5K/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6/https://www.oracle.com/security-alerts/cpujul2022.html
2022-04-04
Published