[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2023-46137":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":27,"aliases":37,"duplicate_of":9,"upstream":40,"downstream":41,"duplicates":72,"related":73,"reserved_at":9,"published_at":80,"modified_at":81,"state":82,"summary":83,"references_raw":91,"kevs":120,"epss":121,"epss_history":124,"metrics":391,"affected":401},"CVE-2023-46137","Twisted is an event-based framework for internet applications. Prior to version 23.10.0rc1, when sending multiple HTTP requests in one TCP packet, twisted.web will process the requests asynchronously without guaranteeing the response order. If one of the endpoints is controlled by an attacker, the attacker can delay the response on purpose to manipulate the response of the second request when a victim launched two requests using HTTP pipeline. Version 23.10.0rc1 contains a patch for this issue.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-444","Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')","The product acts as an intermediary HTTP agent\n         (such as a proxy or firewall) in the data flow between two\n         entities such as a client and server, but it does not\n         interpret malformed HTTP requests or responses in ways that\n         are consistent with how the messages will be processed by\n         those entities that are at the ultimate destination.","weakness","Incomplete","Base",[19,23],{"id":20,"name":21,"techniques":22},"CAPEC-273","HTTP Response Smuggling",[],{"id":24,"name":25,"techniques":26},"CAPEC-33","HTTP Request Smuggling",[],[28],{"_key":29,"name":30,"source":31,"url":32,"maturity":33,"reliability_score":34,"verified":35,"type":9,"platforms":36,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_TWISTED_TWISTED","Twisted","github","https://github.com/twisted/twisted/security/advisories/GHSA-rv6r-3f5q-9rgx","poc",0.3,false,[],[38,39],"GHSA-xc8x-vp79-p3wm","PYSEC-2023-224",[],[42,44,46,48,50,52,54,56,58,60,62,64,66,68,70],{"_key":43},"SUSE-SU-2023:4830-1",{"_key":45},"UBUNTU-CVE-2023-46137",{"_key":47},"SUSE-SU-2023:4490-1",{"_key":49},"SUSE-SU-2023:4607-1",{"_key":51},"SUSE-SU-2023:4608-1",{"_key":53},"OPENSUSE-SU-2024:13430-1",{"_key":55},"DLA-3970-1",{"_key":57},"DSA-5797-1",{"_key":59},"MGASA-2025-0054",{"_key":61},"USN-6575-1",{"_key":63},"DEBIAN-CVE-2023-46137",{"_key":65},"RHSA-2024:0322",{"_key":67},"RHSA-2024:1516",{"_key":69},"RHSA-2024:1518",{"_key":71},"RHSA-2024:1640",[],[74,75,76,77,78,79],{"_key":43},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":59},"2023-10-25T20:56:27.320Z","2025-11-03T21:49:56.068Z","Modified",{"cisa_kev":35,"cisa_ransomware":35,"cisa_vendor":9,"epss_severity":84,"epss_score":85,"severity":86,"severity_score":87,"severity_version":88,"severity_source":89,"severity_vector":90,"severity_status":82},"low",0.0074,"medium",5.3,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",[92,103,107,111,115],{"url":93,"sources":94,"tags":97},"https://github.com/twisted/twisted/security/advisories/GHSA-xc8x-vp79-p3wm",[89,95,96],"nvd","osv_pypi",[98,99,100,101,102],"X Refsource CONFIRM","Exploit","Vendor Advisory","WEB","Advisory",{"url":104,"sources":105,"tags":106},"https://lists.debian.org/debian-lts-announce/2024/11/msg00028.html",[89,95,96],[101],{"url":108,"sources":109,"tags":110},"https://nvd.nist.gov/vuln/detail/CVE-2023-46137",[96],[102],{"url":112,"sources":113,"tags":114},"https://github.com/pypa/advisory-database/tree/main/vulns/twisted/PYSEC-2023-224.yaml",[96],[101],{"url":116,"sources":117,"tags":118},"https://github.com/twisted/twisted",[96],[119],"PACKAGE",[],{"date":122,"score":85,"percentile":123},"2026-06-04",0.73289,[125,129,132,135,138,141,144,147,150,154,157,160,163,166,169,173,176,179,182,185,188,191,194,197,199,202,205,208,211,214,217,220,223,226,229,232,235,238,241,244,247,250,253,256,259,262,265,268,271,274,276,279,282,285,288,291,294,296,299,302,305,308,310,313,316,319,322,325,327,329,332,335,338,341,344,347,350,353,355,358,361,365,368,371,374,377,380,383,386,388],{"date":126,"score":127,"percentile":128},"2025-11-04",0.00476,0.64076,{"date":130,"score":127,"percentile":131},"2025-11-05",0.64056,{"date":133,"score":127,"percentile":134},"2025-11-06",0.64059,{"date":136,"score":127,"percentile":137},"2025-11-07",0.64069,{"date":139,"score":127,"percentile":140},"2025-11-08",0.64073,{"date":142,"score":127,"percentile":143},"2025-11-09",0.64065,{"date":145,"score":127,"percentile":146},"2025-11-10",0.6405,{"date":148,"score":127,"percentile":149},"2025-11-11",0.64061,{"date":151,"score":152,"percentile":153},"2025-11-12",0.00645,0.6989,{"date":155,"score":152,"percentile":156},"2025-11-13",0.69896,{"date":158,"score":152,"percentile":159},"2025-11-14",0.69904,{"date":161,"score":152,"percentile":162},"2025-11-15",0.69902,{"date":164,"score":152,"percentile":165},"2025-11-16",0.69899,{"date":167,"score":152,"percentile":168},"2025-11-17",0.69897,{"date":170,"score":171,"percentile":172},"2025-11-18",0.00275,0.47823,{"date":174,"score":171,"percentile":175},"2025-11-19",0.47838,{"date":177,"score":171,"percentile":178},"2025-11-20",0.47819,{"date":180,"score":152,"percentile":181},"2025-11-21",0.69914,{"date":183,"score":152,"percentile":184},"2025-11-22",0.69907,{"date":186,"score":152,"percentile":187},"2025-11-23",0.69892,{"date":189,"score":152,"percentile":190},"2025-11-24",0.69884,{"date":192,"score":152,"percentile":193},"2025-11-25",0.69885,{"date":195,"score":152,"percentile":196},"2025-11-26",0.69891,{"date":198,"score":152,"percentile":196},"2025-11-27",{"date":200,"score":152,"percentile":201},"2025-11-28",0.69882,{"date":203,"score":152,"percentile":204},"2025-11-29",0.69869,{"date":206,"score":152,"percentile":207},"2025-11-30",0.69864,{"date":209,"score":152,"percentile":210},"2025-12-01",0.70008,{"date":212,"score":152,"percentile":213},"2025-12-02",0.70016,{"date":215,"score":152,"percentile":216},"2025-12-03",0.70013,{"date":218,"score":152,"percentile":219},"2025-12-04",0.69858,{"date":221,"score":152,"percentile":222},"2025-12-05",0.69873,{"date":224,"score":152,"percentile":225},"2025-12-06",0.69879,{"date":227,"score":152,"percentile":228},"2025-12-07",0.69877,{"date":230,"score":152,"percentile":231},"2025-12-08",0.69881,{"date":233,"score":152,"percentile":234},"2025-12-09",0.69913,{"date":236,"score":152,"percentile":237},"2025-12-10",0.69955,{"date":239,"score":152,"percentile":240},"2025-12-11",0.69978,{"date":242,"score":152,"percentile":243},"2025-12-12",0.70004,{"date":245,"score":152,"percentile":246},"2025-12-13",0.70006,{"date":248,"score":152,"percentile":249},"2025-12-14",0.70009,{"date":251,"score":152,"percentile":252},"2025-12-15",0.70005,{"date":254,"score":152,"percentile":255},"2025-12-16",0.70011,{"date":257,"score":152,"percentile":258},"2025-12-17",0.70026,{"date":260,"score":152,"percentile":261},"2025-12-18",0.70055,{"date":263,"score":152,"percentile":264},"2025-12-19",0.70071,{"date":266,"score":152,"percentile":267},"2025-12-20",0.70068,{"date":269,"score":152,"percentile":270},"2025-12-21",0.70058,{"date":272,"score":152,"percentile":273},"2025-12-22",0.70054,{"date":275,"score":152,"percentile":273},"2025-12-23",{"date":277,"score":152,"percentile":278},"2025-12-24",0.70063,{"date":280,"score":152,"percentile":281},"2025-12-25",0.70088,{"date":283,"score":152,"percentile":284},"2025-12-26",0.70087,{"date":286,"score":152,"percentile":287},"2025-12-27",0.70119,{"date":289,"score":152,"percentile":290},"2025-12-28",0.7006,{"date":292,"score":152,"percentile":293},"2025-12-29",0.70056,{"date":295,"score":152,"percentile":267},"2025-12-30",{"date":297,"score":152,"percentile":298},"2025-12-31",0.70089,{"date":300,"score":152,"percentile":301},"2026-01-01",0.70245,{"date":303,"score":152,"percentile":304},"2026-01-02",0.70238,{"date":306,"score":152,"percentile":307},"2026-01-03",0.70239,{"date":309,"score":152,"percentile":281},"2026-01-04",{"date":311,"score":152,"percentile":312},"2026-01-05",0.7008,{"date":314,"score":152,"percentile":315},"2026-01-06",0.70086,{"date":317,"score":152,"percentile":318},"2026-01-07",0.70101,{"date":320,"score":152,"percentile":321},"2026-01-08",0.70116,{"date":323,"score":152,"percentile":324},"2026-01-09",0.70122,{"date":326,"score":152,"percentile":324},"2026-01-10",{"date":328,"score":152,"percentile":321},"2026-01-11",{"date":330,"score":152,"percentile":331},"2026-01-12",0.70111,{"date":333,"score":152,"percentile":334},"2026-01-13",0.70108,{"date":336,"score":152,"percentile":337},"2026-01-14",0.70136,{"date":339,"score":152,"percentile":340},"2026-01-15",0.70143,{"date":342,"score":152,"percentile":343},"2026-01-16",0.70161,{"date":345,"score":152,"percentile":346},"2026-01-17",0.70154,{"date":348,"score":152,"percentile":349},"2026-01-18",0.70133,{"date":351,"score":152,"percentile":352},"2026-01-19",0.70125,{"date":354,"score":152,"percentile":349},"2026-01-20",{"date":356,"score":152,"percentile":357},"2026-01-21",0.70137,{"date":359,"score":152,"percentile":360},"2026-01-22",0.70149,{"date":362,"score":363,"percentile":364},"2026-01-23",0.00594,0.68736,{"date":366,"score":363,"percentile":367},"2026-01-24",0.68747,{"date":369,"score":363,"percentile":370},"2026-01-25",0.68716,{"date":372,"score":363,"percentile":373},"2026-01-26",0.68709,{"date":375,"score":363,"percentile":376},"2026-01-27",0.68712,{"date":378,"score":363,"percentile":379},"2026-01-28",0.68723,{"date":381,"score":363,"percentile":382},"2026-01-29",0.68724,{"date":384,"score":363,"percentile":385},"2026-01-30",0.6873,{"date":387,"score":363,"percentile":364},"2026-01-31",{"date":389,"score":363,"percentile":390},"2026-02-01",0.68883,[392,397,399],{"source":89,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":393,"cvss_v4_0":9},{"baseScore":87,"baseSeverity":394,"vectorString":90,"impactScore":395,"exploitabilityScore":396},"MEDIUM",2.3,10,{"source":95,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":398,"cvss_v4_0":9},{"baseScore":87,"baseSeverity":394,"vectorString":90,"impactScore":395,"exploitabilityScore":396},{"source":96,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":400,"cvss_v4_0":9},{"baseScore":87,"baseSeverity":9,"vectorString":90,"impactScore":395,"exploitabilityScore":396},[402,413],{"ecosystem":403,"name":404,"vendor":403,"product":404,"cpe_part":9,"purl_type":405,"purl_namespace":9,"purl_name":404,"source":9,"versions":406},"PyPI","twisted","pypi",[407],{"version":408,"is_range":409,"range_type":410,"version_start":9,"version_start_type":9,"version_end":411,"version_end_type":412,"fixed_in":9},"lt23_10_0rc1",true,"ecosystem","23.10.0rc1","excluding",{"ecosystem":9,"name":404,"vendor":404,"product":404,"cpe_part":414,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":415},"a",[416,418],{"version":411,"is_range":35,"range_type":89,"version_start":411,"version_start_type":417,"version_end":411,"version_end_type":417,"fixed_in":9},"including",{"version":419,"is_range":409,"range_type":420,"version_start":9,"version_start_type":9,"version_end":421,"version_end_type":417,"fixed_in":9},"lte22.8.0","cpe","22.8.0"]