[Bug 299174] devel/py-twisted: Update to 26.4.0 (fixes TLS with py-pyopenssl >= 26.2; CVE-2026-42304)

From: <bugzilla-noreply_at_freebsd.org>
Date: Tue, 06 Oct 2026 07:44:28 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=299174

            Bug ID: 299174
           Summary: devel/py-twisted: Update to 26.4.0 (fixes TLS with
                    py-pyopenssl >= 26.2; CVE-2026-42304)
           Product: Ports & Packages
           Version: Latest
          Hardware: Any
               URL: https://github.com/twisted/twisted/issues/12500
                OS: Any
            Status: New
          Severity: Affects Many People
          Priority: ---
         Component: Individual Port(s)
          Assignee: python@FreeBSD.org
          Reporter: vladimir.bychik.dev@gmail.com
          Assignee: python@FreeBSD.org
                CC:
             Flags: maintainer-feedback?(python@FreeBSD.org)

devel/py-twisted is still at 25.5.0, which is incompatible with
security/py-pyopenssl >= 26.2.0 (now in ports and in 2026Q3).

pyOpenSSL 26.2.0 made it an error to call any mutating method on an
OpenSSL.SSL.Context after that Context has been used to create a Connection
(deprecated with a warning since 25.1). Twisted 25.5.0 does exactly that in
twisted/protocols/tls.py, TLSMemoryBIOProtocol._createConnection():

    if IProtocolNegotiationFactory.providedBy(self.wrappedFactory):
        protocols = self.wrappedFactory.acceptableProtocols()
        context = connection.get_context()
        _setAcceptableProtocols(context, protocols)   # -> ValueError

Since the Connection is created before this call, it fails on every handshake
for any server whose wrapped factory supports protocol negotiation (ALPN), e.g.
twisted.web / net-im/py-matrix-synapse TLS listeners. The connection is dropped
and clients see "unexpected eof while reading". Upstream also identified a
second mutation in twisted/internet/_sslverify.py when a Context is reused
across connections. This is the root cause of bug 297639.

Observed with: FreeBSD 15, py312-matrix-synapse-1.151.0_4,
py312-twisted-25.5.0, py312-pyopenssl-26.2.0.

Upstream fix: Twisted 26.4.0 (2026-05-11), "twisted.internet.ssl and
twisted.protocols.tls no longer mutate the pyOpenSSL context after creating
pyOpenSSL connections" (https://github.com/twisted/twisted/issues/12500).

Twisted 26.4.0 also fixes CVE-2026-42304 (DoS via resource exhaustion during
DNS name decompression in twisted.names), which affects all versions before
26.4.0rc2.

Please update devel/py-twisted to 26.4.0 or later (and add a vuxml entry for
CVE-2026-42304). Consumers should be exp-run, since the TLS internals changed.

Workarounds until then: keep security/py-pyopenssl < 26.2.0, or locally wrap
the _setAcceptableProtocols() call in tls.py with try/except ValueError (which
disables ALPN, falling back to HTTP/1.1).

-- 
You are receiving this mail because:
You are on the CC list for the bug.
You are the assignee for the bug.