maintainer-feedback requested: [Bug 299174] devel/py-twisted: Update to 26.4.0 (fixes TLS with py-pyopenssl >= 26.2; CVE-2026-42304)
Date: Tue, 06 Oct 2026 07:44:28 UTC
Bugzilla Automation <bugzilla@FreeBSD.org> has asked freebsd-python (Nobody)
<python@FreeBSD.org> for maintainer-feedback:
Bug 299174: devel/py-twisted: Update to 26.4.0 (fixes TLS with py-pyopenssl >=
26.2; CVE-2026-42304)
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=299174
--- Description ---
devel/py-twisted is still at 25.5.0, which is incompatible with
security/py-pyopenssl >= 26.2.0 (now in ports and in 2026Q3).
pyOpenSSL 26.2.0 made it an error to call any mutating method on an
OpenSSL.SSL.Context after that Context has been used to create a Connection
(deprecated with a warning since 25.1). Twisted 25.5.0 does exactly that in
twisted/protocols/tls.py, TLSMemoryBIOProtocol._createConnection():
if IProtocolNegotiationFactory.providedBy(self.wrappedFactory):
protocols = self.wrappedFactory.acceptableProtocols()
context = connection.get_context()
_setAcceptableProtocols(context, protocols) # -> ValueError
Since the Connection is created before this call, it fails on every handshake
for any server whose wrapped factory supports protocol negotiation (ALPN), e.g.
twisted.web / net-im/py-matrix-synapse TLS listeners. The connection is dropped
and clients see "unexpected eof while reading". Upstream also identified a
second mutation in twisted/internet/_sslverify.py when a Context is reused
across connections. This is the root cause of bug 297639.
Observed with: FreeBSD 15, py312-matrix-synapse-1.151.0_4,
py312-twisted-25.5.0, py312-pyopenssl-26.2.0.
Upstream fix: Twisted 26.4.0 (2026-05-11), "twisted.internet.ssl and
twisted.protocols.tls no longer mutate the pyOpenSSL context after creating
pyOpenSSL connections" (https://github.com/twisted/twisted/issues/12500).
Twisted 26.4.0 also fixes CVE-2026-42304 (DoS via resource exhaustion during
DNS name decompression in twisted.names), which affects all versions before
26.4.0rc2.
Please update devel/py-twisted to 26.4.0 or later (and add a vuxml entry for
CVE-2026-42304). Consumers should be exp-run, since the TLS internals changed.
Workarounds until then: keep security/py-pyopenssl < 26.2.0, or locally wrap
the _setAcceptableProtocols() call in tls.py with try/except ValueError (which
disables ALPN, falling back to HTTP/1.1).