Twistedmatrix is a Python networking and asynchronous programming framework whose vulnerability footprint centers on several modular libraries including treq, twistedweb, and txaws, each exposing web-facing or credential-handling surfaces. The recurring weakness classes—including sensitive information disclosure, forced browsing, improper certificate validation, and command injection—reflect the input-validation and authentication demands of HTTP clients and server components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Twistedmatrix over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50688MEDIUM A command injection vulnerability exists in TwistedWeb (version 14.0.0) due to improper input sanitization in the file upload functionality. An attacker can exploit this vulnerabil | Aug 5, 2025 | 6.5 | 24 | NO | NO |
CVE-2022-23607MEDIUM treq is an HTTP library inspired by requests but written on top of Twisted's Agents. Treq's request methods (`treq.get`, `treq.post`, etc.) and `treq.client.HTTPClient` constructor | Feb 1, 2022 | 6.5 | 22 | NO | NO |
CVE-2017-1000007MEDIUM txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure. | Jul 17, 2017 | 5.9 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Twistedmatrix.
Media articles that mention a CVE ID that affects a product developed by Twistedmatrix — matched by CVE ID, not by vendor name.