---
id: CVE-2022-39348
aliases:
  - GHSA-vg46-2rrj-3647
  - PYSEC-2026-1055
title: Twisted vulnerable to NameVirtualHost Host header injection
summary: Twisted vulnerable to NameVirtualHost Host header injection
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
vendor: twisted
product: twisted
ecosystem: pip
affected:
  - 'twisted >= 0.9.4, < 22.10.0rc1'
patched:
  - twisted 22.10.0rc1
published: '2022-10-26'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-vg46-2rrj-3647'
references:
  - url: 'https://github.com/twisted/twisted/security/advisories/GHSA-vg46-2rrj-3647'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-39348'
  - url: >-
      https://github.com/twisted/twisted/commit/f2f5e81c03f14e253e85fe457e646130780db40b
  - url: >-
      https://github.com/twisted/twisted/commit/f49041bb67792506d85aeda9cf6157e92f8048f4
  - url: 'https://github.com/twisted/twisted'
  - url: 'https://lists.debian.org/debian-lts-announce/2022/11/msg00038.html'
  - url: 'https://lists.debian.org/debian-lts-announce/2024/11/msg00028.html'
  - url: 'https://security.gentoo.org/glsa/202301-02'
tags:
  - osv
  - pip
epss: 0.01244
epssPercentile: 0.67975
ingestedAt: '2026-07-08T18:25:53.322Z'
---

## Overview

When the host header does not match a configured host, `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response allowing HTML and script injection.

Example configuration:
```python
from twisted.web.server import Site
from twisted.web.vhost import NameVirtualHost
from twisted.internet import reactor

resource = NameVirtualHost()
site = Site(resource)
reactor.listenTCP(8080, site)
reactor.run()
```
Output:
```
❯ curl -H"Host:<h1>HELLO THERE</h1>" http://localhost:8080/

<html>
  <head><title>404 - No Such Resource</title></head>
  <body>
    <h1>No Such Resource</h1>
    <p>host b'<h1>hello there</h1>' not in vhost map</p>
  </body>
</html>
```

This vulnerability was introduced in f49041bb67792506d85aeda9cf6157e92f8048f4 and first appeared in the 0.9.4 release.

## Affected packages

- `twisted >= 0.9.4, < 22.10.0rc1`

## Remediation

Upgrade to a patched release:

- `twisted 22.10.0rc1`
