UBUNTU-CVE-2025-67724

Source
https://ubuntu.com/security/CVE-2025-67724
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67724.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-67724
Upstream
Downstream
Related
Published
2025-12-12T06:15:00Z
Modified
2026-01-14T03:20:48.527704Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

References

Affected packages

Ubuntu:24.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.4.0-1ubuntu0.4?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-1ubuntu0.4

Affected versions

6.*

6.3.2-1
6.4.0-0ubuntu1
6.4.0-1
6.4.0-1build1
6.4.0-1ubuntu0.1
6.4.0-1ubuntu0.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.4.0-1ubuntu0.4"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67724.json"

Ubuntu:25.04

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.4.2-1ubuntu0.25.04.3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.2-1ubuntu0.25.04.3

Affected versions

6.*

6.4.1-2
6.4.1-3
6.4.2-1
6.4.2-1ubuntu0.25.04.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.4.2-1ubuntu0.25.04.3"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67724.json"

Ubuntu:25.10

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.4.2-3ubuntu0.2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.2-3ubuntu0.2

Affected versions

6.*

6.4.2-1
6.4.2-2
6.4.2-2ubuntu1
6.4.2-3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.4.2-3ubuntu0.2"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67724.json"

Ubuntu:Pro:16.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@4.2.1-1ubuntu3.1+esm2?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.2.1-1ubuntu2
4.2.1-1ubuntu3
4.2.1-1ubuntu3.1
4.2.1-1ubuntu3.1+esm1
4.2.1-1ubuntu3.1+esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python-tornado",
            "binary_version": "4.2.1-1ubuntu3.1+esm2"
        },
        {
            "binary_name": "python3-tornado",
            "binary_version": "4.2.1-1ubuntu3.1+esm2"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67724.json"

Ubuntu:Pro:18.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@4.5.3-1ubuntu0.2+esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*

4.5.1-2.1~build2
4.5.2-1
4.5.3-1
4.5.3-1ubuntu0.1
4.5.3-1ubuntu0.2
4.5.3-1ubuntu0.2+esm1
4.5.3-1ubuntu0.2+esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python-tornado",
            "binary_version": "4.5.3-1ubuntu0.2+esm2"
        },
        {
            "binary_name": "python3-tornado",
            "binary_version": "4.5.3-1ubuntu0.2+esm2"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67724.json"

Ubuntu:Pro:20.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.0.3+really5.1.1-3ubuntu0.1~esm3?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.0.3+really5.1.1-3ubuntu0.1~esm3

Affected versions

5.*

5.1.1-4ubuntu1
5.1.1-4ubuntu5

6.*

6.0.3+really5.1.1-2
6.0.3+really5.1.1-2build1
6.0.3+really5.1.1-2build2
6.0.3+really5.1.1-3
6.0.3+really5.1.1-3ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.0.3+really5.1.1-3ubuntu0.1~esm3"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67724.json"

Ubuntu:Pro:22.04:LTS

python-tornado

Package

Name
python-tornado
Purl
pkg:deb/ubuntu/python-tornado@6.1.0-3ubuntu0.1~esm4?arch=source&distro=esm-apps/jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.0-3ubuntu0.1~esm4

Affected versions

6.*

6.1.0-1build1
6.1.0-2
6.1.0-3
6.1.0-3build1
6.1.0-3ubuntu0.1~esm1
6.1.0-3ubuntu0.1~esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-tornado",
            "binary_version": "6.1.0-3ubuntu0.1~esm4"
        }
    ],
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-67724.json"