VulnSea

tornado has 12 CVEs on record between 2024 and 2026. 3 were published in the last 90 days. The busiest recent month was December 2025 with 3. The median CVSS is 7.0 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
Last 90 days
3 prev 2

Products

  • tornado 12
12
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

tornado vulnerabilities

CVEs affecting tornado, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

GHSA-wwv5-g3v4-889xLow
3w ago

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_…

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

Sunlittornado · tornadovia OSV
GHSA-8423-8fgw-73vqMedium
3w ago

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

Sunlittornado · tornadovia OSV
CVE-2026-82397High· 7.5
3w ago

Tornado is a Python web framework and asynchronous networking library

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. Reques…

Twilighttornado · tornadoEPSS 0.35%via NVD
GHSA-pw6j-qg29-8w7fMedium· 5.9
3mo ago

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

Sunlittornado · tornadovia OSV
CVE-2026-49854Low· 3.7
3mo ago

Tornado has out-of-bounds memory access via C extension

Tornado has out-of-bounds memory access via C extension

Sunlittornado · tornadoEPSS 0.34%via OSV
CVE-2025-67726High· 7.5
9mo ago

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing…

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.…

Twilighttornado · tornadoEPSS 0.53%via OSV
CVE-2025-67725High· 7.5
9mo ago

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP req…

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method.…

Twilighttornado · tornadoEPSS 0.56%via OSV
CVE-2025-67724Medium· 6.1
9mo ago

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used un…

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default erro…

Sunlittornado · tornadoEPSS 0.24%via OSV
CVE-2025-47287High· 7.5
1y ago

Tornado vulnerable to excessive logging caused by malformed multipart form data

Tornado vulnerable to excessive logging caused by malformed multipart form data

Twilighttornado · tornadoEPSS 0.74%via OSV
CVE-2024-52804High· 7.5
1y ago

Tornado has an HTTP cookie parsing DoS vulnerability

Tornado has an HTTP cookie parsing DoS vulnerability

Twilighttornado · tornadoEPSS 1.0%via OSV
GHSA-w235-7p84-xx57Medium· 6.5
2y ago

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

Sunlittornado · tornadovia OSV
GHSA-753j-mpmx-qq6gMedium· 5.3
2y ago

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

Sunlittornado · tornadovia OSV
tornado vulnerabilities (CVEs) · VulnSea