Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-41810

28
FAUCET Score

CVE-2024-41810 is an HTML injection vulnerability in the twisted.web.util.redirectTo function of the Twisted framework, affecting versions prior to 24.7.0rc1. This flaw can lead to Reflected Cross-Site Scripting (XSS) if an attacker can control the redirect URL. Rated as Medium severity (CVSS 6.1), it requires user interaction and has a high FAUCET Risk Score of 98/100, indicating significant potential impact. While not actively exploited in the wild and lacking Metasploit or ExploitDB entries, Nuclei templates for detection exist, and there is currently no community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 24.3.0CPE matchmatch criteria
cpe:2.3:a:twisted:twisted:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.18%
Probability of exploitation in next 30 days
EPSS Percentile
64.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2024-41810 · Jul 31, 2024
This CVE's current EPSS score of 0.0118 is in the 77th percentile among its peer group of 26,219 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (20)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: cbl2 python-twisted 22.10.0-4 on CBL Mariner 2.0Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: 17270-16823Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: 17672-17084Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: 18264-17084Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: 20027-17086Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: cbl2 python-twisted 22.10.0-3 on CBL Mariner 2.0Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: azl3 python-twisted 22.10.0-3 on Azure Linux 3.0Fixed in: 22.10.0-3
microsoftpatch availablevia msrc
Product: azl3 python-twisted 22.10.0-4 on Azure Linux 3.0Fixed in: 22.10.0-3
pippatch availablevia ghsa
Product: twistedFixed in: 24.7.0rc1
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Automation Platform 2.4 for RHEL 8Fixed in: automation-controller-0:4.5.12-1.el8ap
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Automation Platform 2.4 for RHEL 9Fixed in: automation-controller-0:4.5.12-1.el9ap
View patch
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: python3x-twisted
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: python-twisted
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: python-twisted
redhatend of lifevia redhat_api
Product: Red Hat Ansible Automation Platform 1.2Fixed in: ansible-tower

Vendor Advisories (4)

microsoft2024-Sep/CVE-2024-41810

CVE-2024-41810

Sep 10, 2024
pipGHSA-cf56-g6w6-pqq2medium

Twisted vulnerable to HTML injection in HTTP redirect body

Jul 29, 2024
redhatCVE-2024-41810Moderate

python-twisted: Reflected XSS via HTML Injection in Redirect Response

Jul 29, 2024
microsoft2024-Jul/CVE-2024-41810Moderate

HTML injection in HTTP redirect body

Jul 9, 2024

References

lists.debian.org / debian-lts-announce/2024/11/msg00028.html
github.com / twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33
Patch
github.com / twisted/twisted/security/advisories/GHSA-cf56-g6w6-pqq2
Vendor Advisory