# CVE-2024-41671

## Summary

- **CVE ID:** CVE-2024-41671
- **Severity:** HIGH
- **CVSS Score:** 8.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L)
- **CWE:** CWE-444
- **Published:** Jul 29, 2024
- **Last Modified:** Mar 13, 2026

## Description

Twisted is an event-based framework for internet applications, supporting Python 3.6+. The HTTP 1.0 and 1.1 server provided by twisted.web could process pipelined HTTP requests out-of-order, possibly resulting in information disclosure. This vulnerability is fixed in 24.7.0rc1.

## Affected Products

- twisted — twisted (<= 24.3.0)

## References

- [CNA](https://github.com/twisted/twisted/security/advisories/GHSA-c8m8-j448-xjx7)
- [CNA](https://github.com/twisted/twisted/commit/046a164f89a0f08d3239ecebd750360f8914df33)
- [CNA](https://github.com/twisted/twisted/commit/4a930de12fb67e88fefcb8822104152f42b27abc)
- [CVE](https://www.vicarius.io/vsociety/posts/disordered-http-pipeline-in-twistedweb-cve-2024-4167)
- [CVE](https://lists.debian.org/debian-lts-announce/2024/11/msg00028.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.86%
- **EPSS Percentile:** 56.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._