Tornadoweb

Tornado

23 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 01.10.2026 10:42:05
  • Zuletzt bearbeitet 01.10.2026 20:17:23

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists i...

  • EPSS 0.53%
  • Veröffentlicht 01.10.2026 10:42:04
  • Zuletzt bearbeitet 06.10.2026 01:16:32

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb...

  • EPSS 0.47%
  • Veröffentlicht 01.10.2026 10:42:04
  • Zuletzt bearbeitet 01.10.2026 15:17:26

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET...

  • EPSS 0.21%
  • Veröffentlicht 15.09.2026 15:18:33
  • Zuletzt bearbeitet 17.09.2026 16:18:32

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client...

  • EPSS 0.22%
  • Veröffentlicht 15.09.2026 15:18:32
  • Zuletzt bearbeitet 08.10.2026 16:17:59

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data ...

  • EPSS 0.41%
  • Veröffentlicht 15.09.2026 15:18:31
  • Zuletzt bearbeitet 16.09.2026 13:42:49

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient ...

  • EPSS 0.24%
  • Veröffentlicht 15.09.2026 15:17:53
  • Zuletzt bearbeitet 28.09.2026 14:10:00

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers o...

  • EPSS 0.35%
  • Veröffentlicht 15.09.2026 15:17:52
  • Zuletzt bearbeitet 28.09.2026 14:10:00

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind prox...

  • EPSS 0.37%
  • Veröffentlicht 15.09.2026 15:17:52
  • Zuletzt bearbeitet 17.09.2026 15:16:39

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and s...

  • EPSS 0.35%
  • Veröffentlicht 31.08.2026 21:28:13
  • Zuletzt bearbeitet 09.09.2026 21:09:13

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._exe...