CVE-2019-12855: Twisted

High severity, CVSS 7.4. EPSS: 1.8% chance of exploitation in the next 30 days.

In words.protocols.jabber.xmlstream in Twisted through 19.2.1, XMPP support did not verify certificates when used with TLS, allowing an attacker to MITM connections.

Affected products

  • Twisted Twisted: up to and including 19.2.1

Published 2019-06-16. Last modified 2026-06-17.