Disclosure summary
### Summary `wildcardToRegexp()` in `twisted/mail/imap4.py` converts IMAP LIST/LSUB wildcard patterns to Python regular expressions. It substitutes the two IMAP wildcards (`*` → `(?:.*?)` and `%` → `(?:(?:[^\\/])*?)`) but passes every other character through unchanged to `re.compile()`. This means that an authenticated IMAP client can send a quoted pattern string containing arbitrary regex syntax - including catastrophic-backtracking constructs such as `(a+)+z`. Because Twisted runs a cooperative, single-threaded reactor, a blocking regex match freezes **all** I/O on the server for the duration of the match. --- ## Vulnerable Code ### `twisted/mail/imap4.py` ```python # line 4595 def wildcardToRegexp(wildcard, delim=None): wildcard = wildcard.replace("*", "(?:.*?)") if delim is None: wildcard = wildcard.replace("%", "(?:.*?)") else: wildcard = wildcard.replace("%", "(?:(?:[^%s])*?)" % re.escape(delim)) return re.compile(wildcard, re.I) # ← user input compiled verbatim ``` ```python # line 4993 class MemoryAccountWithoutNamespaces: def listMailboxes(self, ref, wildcard): ref = self._inferiorNames(_parseMbox(ref.upper())) wildcard = wildcardToRegexp(wildcard, "/") # ← user-supplied w
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-8pqf-f4m5-798g
Open original source · Updated Oct 07, 2026
Twisted: IMAP wildcardToRegexp() ReDoS
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | Twisted | Not supplied |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:18:30-04:00
MODIFIED 2026-10-07T12:18:31-04:00
INGESTED 2026-10-08T12:05:11-04:00