Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106454— Twisted: IMAP wildcardToRegexp() ReDoS

Quick assessment

Affected
twisted twisted
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Twisted 是一个面向互联网应用程序的事件驱动框架,支持 Python 3.6 及以上版本。在 25.5.0 及更早版本中,位于 中的 函数虽然能够正确转换 IMAP 通配符(* 和 %),但会将经过身份验证的客户端提供的 LIST 或 LSUB 命令中的其他字符直接传递给 。这导致攻击者可以构造嵌套或计算复杂度极高的正则表达式模式,在对邮箱名称进行匹配时引发灾难性的回溯行为(catastrophic backtracking)。由于 Twisted 采用协作式单线程反应器模型,此类阻塞性匹配操作会使服务器在所

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106454

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Twisted: IMAP wildcardToRegexp() ReDoS
Source: CVE Program / CVE List V5
Vulnerability Description
Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and earlier, wildcardToRegexp() in twisted/mail/imap4.py translates the IMAP asterisk and percent wildcards but passes all other characters from an authenticated client's LIST or LSUB pattern directly to re.compile(), allowing nested or otherwise expensive regular expression constructs to cause catastrophic backtracking when matched against mailbox names. Because Twisted uses a cooperative single-threaded reactor, the blocking match suspends all server input and output for the duration of the match. No fixed release is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1333
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
twisted twisted <= 25.5.0 -

II. Public POCs for CVE-2026-106454

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106454

请登录查看更多情报信息。

Other References for CVE-2026-106454 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-106454

No comments yet


Leave a comment