Skip to main content

Vendor/product archive

tornadoweb / tornado CVEs

Beta · best-effort

10 CVEs tagged to tornadoweb / tornado0 Critical, 6 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-35536

Published Apr 3, 2026

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted charact…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-31958

Published Mar 11, 2026

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the m…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-67726

Published Dec 12, 2025

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potent…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67725

Published Dec 12, 2025

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67724

Published Dec 12, 2025

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47287

Published May 15, 2025

Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues try…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52804

Published Nov 22, 2024

Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic compl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28370

Published May 25, 2023

Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attac…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9720

Published Jan 24, 2020

Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREAC…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2374

Published May 23, 2012

CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1