Tornado is a lightweight Python web framework and asynchronous networking library that, despite a narrow product focus, occupies a prominent position in the ecosystem of event-driven web servers and real-time applications. Its vulnerability profile centers on resource-management and input-validation weaknesses—including uncontrolled resource consumption, allocation without limits, and improper handling of special elements—that reflect the demands of handling asynchronous I/O and parsing untrusted network input at scale. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tornadoweb over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31958HIGH Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the ma | Mar 11, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-67726HIGH Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potenti | Dec 12, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-67725HIGH Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for | Dec 12, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-47287HIGH Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues tryi | May 15, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-67724MEDIUM Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be | Dec 12, 2025 | 6.1 | 24 | NO | NO |
CVE-2026-35536MEDIUM In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characte | Apr 3, 2026 | 5.3 | 22 | NO | NO |
CVE-2024-52804HIGH Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic comple | Nov 22, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-28370MEDIUM Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack | May 25, 2023 | 6.1 | 21 | NO | NO |
CVE-2014-9720MEDIUM Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH | Jan 24, 2020 | 6.5 | 20 | NO | NO |
CVE-2012-2374MEDIUM CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP | May 23, 2012 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tornadoweb.
Media articles that mention a CVE ID that affects a product developed by Tornadoweb — matched by CVE ID, not by vendor name.