Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2938-1 | twisted security update |
EUVD |
EUVD-2022-0344 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version identifier. This ends up with a buffer using all the available memory. The attach is a simple as `nc -rv localhost 22 < /dev/zero`. A patch is available in version 22.2.0. There are currently no known workarounds. |
Github GHSA |
GHSA-rv6r-3f5q-9rgx | Twisted SSH client and server deny of service during SSH handshake. |
Ubuntu USN |
USN-5354-1 | Twisted vulnerabilities |
Ubuntu USN |
USN-5354-2 | Twisted vulnerability |
Tue, 22 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Nov 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Twisted
Twisted twisted |
|
| CPEs | cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Twistedmatrix
Twistedmatrix twisted |
Twisted
Twisted twisted |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T18:21:08.759Z
Reserved: 2021-11-16T00:00:00.000Z
Link: CVE-2022-21716
Updated: 2024-08-03T02:53:34.846Z
Status : Modified
Published: 2022-03-03T21:15:07.747
Modified: 2024-11-25T18:12:24.673
Link: CVE-2022-21716
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN