📦 Tornado

by Tornadoweb

🔍 What is Tornado?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-67726

HIGH CVSS 7.5 Dec 12, 2025

CVE-2025-67726 is a denial-of-service vulnerability in Tornado web framework where inefficient parsing of HTTP header parameters allows attackers to cause quadratic CPU consumption. This affects Torna...

CVE-2025-67725

HIGH CVSS 7.5 Dec 12, 2025

A denial-of-service vulnerability in Tornado web framework allows a single malicious HTTP request to block the server's event loop by exploiting inefficient string concatenation in the HTTPHeaders.add...

CVE-2025-67724

MEDIUM CVSS 5.4 Dec 12, 2025

This vulnerability in Tornado web framework allows attackers to inject malicious content into HTTP headers or execute cross-site scripting (XSS) attacks by passing untrusted data to the 'reason' argum...