CVE-2026-106454 Overview
CVE-2026-106454 affects Twisted, an event-based framework for internet applications supporting Python 3.6+. The vulnerability resides in the wildcardToRegexp() function within twisted/mail/imap4.py. This function translates IMAP wildcard characters but passes all other input directly to re.compile(). An authenticated client can submit a crafted LIST or LSUB pattern containing nested or expensive regular expression constructs. Matching these patterns against mailbox names triggers catastrophic backtracking. Because Twisted uses a cooperative single-threaded reactor, the blocking match suspends all server input and output for its duration. The issue impacts versions 25.5.0 and earlier.
Critical Impact
An authenticated IMAP client can stall the entire Twisted reactor, causing a denial-of-service condition that blocks all concurrent connections handled by the affected server process.
Affected Products
- Twisted framework versions 25.5.0 and earlier
- Applications using twisted.mail.imap4 IMAP server functionality
- Python 3.6+ deployments running Twisted-based IMAP services
Discovery Timeline
- 2026-10-06 - CVE-2026-106454 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-106454
Vulnerability Analysis
The flaw is a Regular Expression Denial of Service (ReDoS) issue classified under [CWE-1333]. The wildcardToRegexp() function translates the IMAP * and % wildcards into non-greedy regex groups. Every other character in the client-supplied pattern is forwarded unchanged to re.compile(). Metacharacters such as (, ), +, ?, [, and ] therefore retain their regex semantics inside mailbox match patterns. An authenticated attacker can craft a pattern containing nested quantifiers or ambiguous alternations. When the resulting pattern is matched against mailbox names during a LIST or LSUB command, Python's regex engine enters catastrophic backtracking.
Root Cause
Twisted runs a cooperative single-threaded reactor. CPU-bound work inside a protocol handler blocks all other I/O until it completes. The root cause is missing escaping of non-wildcard characters before regex compilation. The function assumes the pattern is an IMAP glob, but treats it partially as a regex.
Attack Vector
Exploitation requires valid IMAP credentials. The attacker issues a LIST or LSUB command with a pattern engineered to produce exponential backtracking. The server freezes, denying service to every other connected client until the regex engine terminates.
# Patch from src/twisted/mail/imap4.py (verified from upstream commit)
def wildcardToRegexp(wildcard: str, delim: str | None = None) -> re.Pattern[str]:
# Split on the two IMAP wildcards, escape everything else
parts = re.split(r"([*%])", wildcard)
result = []
for p in parts:
if p == "*":
result.append("(?:.*?)")
elif p == "%":
if delim is None:
result.append("(?:.*?)")
else:
result.append(f"(?:(?:[^{re.escape(delim)}])*?)")
else:
result.append(re.escape(p))
return re.compile("".join(result), re.I)
Source: Twisted commit 2f8a3c2. The fix splits the input on IMAP wildcards and applies re.escape() to every other segment, neutralizing regex metacharacters.
Detection Methods for CVE-2026-106454
Indicators of Compromise
- IMAP LIST or LSUB commands containing regex metacharacters such as (, ), +, nested groupings, or long sequences of alternations.
- Twisted reactor stalls where the process remains alive but stops responding to all connected clients simultaneously.
- Sustained single-core CPU saturation on the Twisted process coinciding with recent authenticated IMAP activity.
Detection Strategies
- Inspect IMAP protocol logs for LIST/LSUB patterns that include characters outside the normal mailbox namespace and IMAP wildcards.
- Monitor reactor latency metrics or application heartbeats to flag periods where I/O processing is paused.
- Correlate authenticated session identifiers with CPU spikes to identify the originating account.
Monitoring Recommendations
- Alert on Twisted processes exceeding sustained CPU thresholds while open client sockets stop producing traffic.
- Capture per-command timing metrics inside the IMAP protocol handler to detect long-running LIST or LSUB operations.
- Review authentication logs for accounts issuing anomalous mailbox search patterns.
How to Mitigate CVE-2026-106454
Immediate Actions Required
- Restrict IMAP access to trusted users and enforce strong authentication, since exploitation requires valid credentials.
- Apply the upstream fix from commit 2f8a3c2 as a backported patch until a tagged release is available.
- Rate-limit LIST and LSUB commands per authenticated session to limit abuse potential.
Patch Information
No fixed release is available as of this review. The upstream fix is tracked in Pull Request #12788 and documented in GitHub Security Advisory GHSA-8pqf-f4m5-798g. Operators running Twisted 25.5.0 or earlier should apply the patch manually.
Workarounds
- Reject LIST and LSUB patterns containing characters other than alphanumerics, the path delimiter, and the IMAP * and % wildcards.
- Enforce a maximum pattern length on IMAP mailbox search commands to limit worst-case regex expansion.
- Run the Twisted IMAP service behind a protocol-aware proxy that validates mailbox pattern syntax before forwarding commands.
# Manual patch application against a vendored Twisted source tree
curl -L https://github.com/twisted/twisted/commit/2f8a3c29246f4eb324690e06a9767a11dc4aec9f.patch \
-o twisted-imap4-redos.patch
cd /path/to/twisted
git apply --check twisted-imap4-redos.patch && git apply twisted-imap4-redos.patch
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.