[Bug 299174] devel/py-twisted: Update to 26.4.0 (fixes TLS with py-pyopenssl >= 26.2; CVE-2026-42304)
Date: Tue, 06 Oct 2026 07:44:28 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=299174
Bug ID: 299174
Summary: devel/py-twisted: Update to 26.4.0 (fixes TLS with
py-pyopenssl >= 26.2; CVE-2026-42304)
Product: Ports & Packages
Version: Latest
Hardware: Any
URL: https://github.com/twisted/twisted/issues/12500
OS: Any
Status: New
Severity: Affects Many People
Priority: ---
Component: Individual Port(s)
Assignee: python@FreeBSD.org
Reporter: vladimir.bychik.dev@gmail.com
Assignee: python@FreeBSD.org
CC:
Flags: maintainer-feedback?(python@FreeBSD.org)
devel/py-twisted is still at 25.5.0, which is incompatible with
security/py-pyopenssl >= 26.2.0 (now in ports and in 2026Q3).
pyOpenSSL 26.2.0 made it an error to call any mutating method on an
OpenSSL.SSL.Context after that Context has been used to create a Connection
(deprecated with a warning since 25.1). Twisted 25.5.0 does exactly that in
twisted/protocols/tls.py, TLSMemoryBIOProtocol._createConnection():
if IProtocolNegotiationFactory.providedBy(self.wrappedFactory):
protocols = self.wrappedFactory.acceptableProtocols()
context = connection.get_context()
_setAcceptableProtocols(context, protocols) # -> ValueError
Since the Connection is created before this call, it fails on every handshake
for any server whose wrapped factory supports protocol negotiation (ALPN), e.g.
twisted.web / net-im/py-matrix-synapse TLS listeners. The connection is dropped
and clients see "unexpected eof while reading". Upstream also identified a
second mutation in twisted/internet/_sslverify.py when a Context is reused
across connections. This is the root cause of bug 297639.
Observed with: FreeBSD 15, py312-matrix-synapse-1.151.0_4,
py312-twisted-25.5.0, py312-pyopenssl-26.2.0.
Upstream fix: Twisted 26.4.0 (2026-05-11), "twisted.internet.ssl and
twisted.protocols.tls no longer mutate the pyOpenSSL context after creating
pyOpenSSL connections" (https://github.com/twisted/twisted/issues/12500).
Twisted 26.4.0 also fixes CVE-2026-42304 (DoS via resource exhaustion during
DNS name decompression in twisted.names), which affects all versions before
26.4.0rc2.
Please update devel/py-twisted to 26.4.0 or later (and add a vuxml entry for
CVE-2026-42304). Consumers should be exp-run, since the TLS internals changed.
Workarounds until then: keep security/py-pyopenssl < 26.2.0, or locally wrap
the _setAcceptableProtocols() call in tls.py with try/except ValueError (which
disables ALPN, falling back to HTTP/1.1).
--
You are receiving this mail because:
You are on the CC list for the bug.
You are the assignee for the bug.