tornadoweb tornado
10 known vulnerabilities in tornadoweb tornado, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-103263 CVSS 8.2 high Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root…
- CVE-2026-103262 CVSS 8.7 high Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers…
- CVE-2026-103261 CVSS 6.9 medium Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause…
- CVE-2026-91992 CVSS 8.2 high Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests…
- CVE-2026-91991 CVSS 6.3 medium Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes…
- CVE-2026-91990 CVSS 8.7 high Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before…
- CVE-2024-58384 CVSS 6.3 medium Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed…
- CVE-2024-14029 CVSS 9.0 critical Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the…
- CVE-2023-54397 CVSS 9.0 critical Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting…
- CVE-2026-82397 CVSS 7.5 high Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded…