CVE-2020-35774: Twitter Twitter-Server

Medium severity, CVSS 5.4. EPSS: 85.6% chance of exploitation in the next 30 days.

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

Affected products

  • Twitter Twitter-Server: before 20.12.0 (fixed in 20.12.0)

Published 2020-12-29. Last modified 2026-06-17.