CVE-2026-49855
- EPSS 0.57%
- Veröffentlicht 14.07.2026 20:45:02
- Zuletzt bearbeitet 16.07.2026 16:19:10
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious ser...
CVE-2026-49854
- EPSS 0.34%
- Veröffentlicht 14.07.2026 20:43:03
- Zuletzt bearbeitet 15.07.2026 19:50:11
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function ...
CVE-2026-49853
- EPSS 0.37%
- Veröffentlicht 14.07.2026 20:41:32
- Zuletzt bearbeitet 21.07.2026 16:17:13
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in pl...
CVE-2026-35536
- EPSS 0.24%
- Veröffentlicht 03.04.2026 02:25:57
- Zuletzt bearbeitet 24.07.2026 21:10:00
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
CVE-2026-31958
- EPSS 0.38%
- Veröffentlicht 11.03.2026 19:27:23
- Zuletzt bearbeitet 01.04.2026 15:23:00
Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronousl...
CVE-2025-67726
- EPSS 0.54%
- Veröffentlicht 12.12.2025 06:13:51
- Zuletzt bearbeitet 07.10.2026 20:10:01
Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.py is used to...
CVE-2025-67725
- EPSS 0.56%
- Veröffentlicht 12.12.2025 05:49:41
- Zuletzt bearbeitet 07.10.2026 20:10:01
Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function...
CVE-2025-67724
- EPSS 0.24%
- Veröffentlicht 12.12.2025 05:36:59
- Zuletzt bearbeitet 07.10.2026 20:10:01
Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where...
CVE-2025-47287
- EPSS 0.74%
- Veröffentlicht 15.05.2025 21:17:55
- Zuletzt bearbeitet 23.12.2025 19:19:44
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to...
CVE-2024-52804
- EPSS 1.05%
- Veröffentlicht 22.11.2024 16:15:34
- Zuletzt bearbeitet 03.11.2025 23:17:15
Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-cr...