VYPR

Tornado

by Tornadoweb

pypi: tornado

Source repositories

CVEs (23)

  • CVE-2026-103261MedOct 1, 2026
    risk 0.27cvss 5.3epss —

    Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded…

  • CVE-2026-49854MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes…

  • CVE-2012-2374May 23, 2012
    risk 0.00cvss —epss 0.01

    CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.

Page 2 of 2