Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3928
  • PyPI/tornado
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop 10 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-mpf4-983q-p7j4
  • PyPI/tornado
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop 02 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-8423-8fgw-73vq
  • PyPI/tornado
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34) 01 Sep
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-wwv5-g3v4-889x
  • PyPI/tornado
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie` 01 Sep
  • Fix available
  • Severity - 2.3 (Low)
GHSA-jhmp-mqwm-3gq8
  • PyPI/tornado
Tornado: Quadratic DoS via Crafted Multipart Parameters 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-c98p-7wgm-6p64
  • PyPI/tornado
Tornado: Quadratic DoS via Repeated Header Coalescing 20 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-pr2v-jx2c-wg9f
  • PyPI/tornado
Tornado vulnerable to Header Injection and XSS via reason argument 20 Jul
  • Fix available
  • Severity - 5.4 (Medium)
PYSEC-2026-3387
  • PyPI/tornado
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient 13 Jul
  • Fix available
  • Severity - 7.7 (High)
PYSEC-2026-3389
  • PyPI/tornado
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-3388
  • PyPI/tornado
Tornado has out-of-bounds memory access via C extension 13 Jul
  • Fix available
  • Severity - 3.7 (Low)
PYSEC-2026-1974
  • PyPI/tornado
Tornado vulnerable to excessive logging caused by malformed multipart form data 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1975
  • PyPI/tornado
Tornado has an HTTP cookie parsing DoS vulnerability 07 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-pw6j-qg29-8w7f
  • PyPI/tornado
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse 15 Jun
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-3x9g-8vmp-wqvf
  • PyPI/tornado
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient 15 Jun
  • Fix available
  • Severity - 7.7 (High)
GHSA-mgf9-4vpg-hj56
  • PyPI/tornado
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) 15 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-cx3h-4qpv-8hc9
  • PyPI/tornado
Tornado has out-of-bounds memory access via C extension 12 Jun
  • Fix available
  • Severity - 3.7 (Low)