VendorsTornado Webtornadoany version
Vulnerabilities

Tornado Web Server Tornado any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-31958
Tornado has a DoS due to too many multipart parts
Published 2026-03-11 · Modified
8.7EPSS 0.005
CVE-2024-52804
Tornado has HTTP cookie parsing DoS vulnerability
Published 2024-11-22 · Modified
7.5EPSS 0.010
CVE-2025-47287
Tornado vulnerable to excessive logging caused by malformed multipart form data
Published 2025-05-15 · Analyzed
7.5EPSS 0.007
CVE-2025-67725
Tornado is Vulnerable to Quadratic DoS via Repeated Header Coalescing
Published 2025-12-12 · Analyzed
7.5EPSS 0.006
CVE-2025-67726
Tornado is Vulnerable to Quadratic DoS via Crafted Multipart Parameters
Published 2025-12-12 · Analyzed
7.5EPSS 0.005
CVE-2026-35536
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Published 2026-04-03 · Analyzed
7.2EPSS 0.003
CVE-2014-9720
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Published 2020-01-24 · Modified
6.5EPSS 0.025
CVE-2023-28370
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL.
Published 2023-05-25 · Modified
6.1EPSS 0.011
CVE-2025-67724
Tornado vulnerable to Header Injection and XSS via reason argument
Published 2025-12-12 · Analyzed
6.1EPSS 0.002
CVE-2012-2374
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.
Published 2012-05-23 · Modified
5.0EPSS 0.014