Vulnerability record · CVE-2022-39348 · published 26 October 2022
CVE-2022-39348: Twisted cross-site scripting vulnerability
Twisted · Twisted
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. In practice this should be very difficult to exploit as being able to modify the Host header of a normal HTTP request implies that one is already in a privileged position. This issue was fixed in version 22.10.0rc1. There are no known workarounds.
Description
Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. In practice this should be very difficult to exploit as being able to modify the Host header of a normal HTTP request implies that one is already in a privileged position. This issue was fixed in version 22.10.0rc1. There are no known workarounds.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/twisted/twisted/commit/f2f5e81c03f14e253e85fe457e646130780db40b | Patch |
| https://github.com/twisted/twisted/commit/f49041bb67792506d85aeda9cf6157e92f8048f4 | Patch |
| https://github.com/twisted/twisted/security/advisories/GHSA-vg46-2rrj-3647 | ExploitPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00038.html | Mailing ListThird Party Advisory |
| https://security.gentoo.org/glsa/202301-02 | Third Party Advisory |
| https://github.com/twisted/twisted/commit/f2f5e81c03f14e253e85fe457e646130780db40b | Patch |
| https://github.com/twisted/twisted/commit/f49041bb67792506d85aeda9cf6157e92f8048f4 | Patch |
| https://github.com/twisted/twisted/security/advisories/GHSA-vg46-2rrj-3647 | ExploitPatchThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2022/11/msg00038.html | Mailing ListThird Party Advisory |
| https://lists.debian.org/debian-lts-announce/2024/11/msg00028.html | |
| https://security.gentoo.org/glsa/202301-02 | Third Party Advisory |
Track CVE-2022-39348 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-39348), CISA KEV, FIRST EPSS (scores of 2026-09-30). This page is refreshed as NVD updates the record.