Tornado
Vendor:
First CVE: May 23, 2012 · Active for 14 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tornado over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 23, 2012
14 years ago
Most Recent CVE
Apr 3, 2026
112 days ago
CVE Severity & Scoring
Tornado10 CVEs
50%
50%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (90.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None6 (60.0%)
Unknown1 (10.0%)
Required3 (30.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (90.0%)
Unknown1 (10.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31958HIGH Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the ma | Mar 11, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-67726HIGH Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potenti | Dec 12, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-67725HIGH Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for | Dec 12, 2025 | 7.5 | 27 | NO | NO |
CVE-2025-47287HIGH Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues tryi | May 15, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-67724MEDIUM Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be | Dec 12, 2025 | 6.1 | 24 | NO | NO |
CVE-2026-35536MEDIUM In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characte | Apr 3, 2026 | 5.3 | 22 | NO | NO |
CVE-2024-52804HIGH Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic comple | Nov 22, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-28370MEDIUM Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack | May 25, 2023 | 6.1 | 21 | NO | NO |
CVE-2014-9720MEDIUM Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH | Jan 24, 2020 | 6.5 | 20 | NO | NO |
CVE-2012-2374MEDIUM CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP | May 23, 2012 | 5.0 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Tornado
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.1 | 1 | 5.0 | 1.4% | 0 | 0 |
| 2.1 | 1 | 5.0 | 1.4% | 0 | 0 |
| 2.0 | 1 | 5.0 | 1.4% | 0 | 0 |
| 1.2.1 | 1 | 5.0 | 1.4% | 0 | 0 |
| 1.2 | 1 | 5.0 | 1.4% | 0 | 0 |
| 1.1.1 | 1 | 5.0 | 1.4% | 0 | 0 |
| 1.1 | 1 | 5.0 | 1.4% | 0 | 0 |
| 1.0.1 | 1 | 5.0 | 1.4% | 0 | 0 |
| 1.0 | 1 | 5.0 | 1.4% | 0 | 0 |