SCA: security update for Twisted (GHSA-8pqf-f4m5-798g)

medium Tenable Self-Hosted Container Security Plugin ID 473712

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Twisted is an event-based framework for internet applications, supporting Python 3.6+. In 25.5.0 and
earlier, wildcardToRegexp() in twisted/mail/imap4.py translates the IMAP asterisk and percent wildcards
but passes all other characters from an authenticated client's LIST or LSUB pattern directly to
re.compile(), allowing nested or otherwise expensive regular expression constructs to cause catastrophic
backtracking when matched against mailbox names. Because Twisted uses a cooperative single-threaded
reactor, the blocking match suspends all server input and output for the duration of the match. No fixed
release is available as of this review. (CVE-2026-106454)

Solution

There is no known solution at this time.

See Also

https://github.com/advisories/GHSA-8pqf-f4m5-798g

Plugin Details

Severity: Medium

ID: 473712

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/7/2026

Updated: 10/7/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 4

Temporal Score: 3

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

CVSS Score Source: CVE-2026-106454

CVSS v3

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-106454