Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Tornado — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in Tornado, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known security vulnerabilities affecting Tornado, a Python web server and application framework, focusing on implementation-specific weaknesses such as denial of service, remote code execution, and access control flaws. The collection spans advisories disclosed from 2012 through the most recent release, covering both legacy and current versions of the library. Readers can use this hub to track Tornado-specific advisories, understand the characteristics of each weakness class, and review the complete vulnerability history for this product. The entries are organized by weakness type, allowing users to filter results by impact severity or publication date. No specific CVE identifiers are required for navigation; instead, the interface emphasizes pattern recognition across the timeline of disclosures.

Vendor: tornadoweb

CVE ID Title CVSS Severity Published
CVE-2026-91992 Tornado before 6.5.7 Credential Leak via Handle Reuse CWE-200 5.9 Medium 2026-09-15
CVE-2026-91990 Tornado before 6.5.8 Memory Amplification DoS via multipart CWE-770 7.5 High 2026-09-15
CVE-2026-91991 Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs CWE-113 5.4 Medium 2026-09-15
CVE-2024-58384 Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient CWE-113 5.4 Medium 2026-09-15
CVE-2024-14029 Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding CWE-444 7.5 High 2026-09-15
CVE-2023-54397 Tornado before 6.3.3 HTTP Request Smuggling via Content-Length CWE-444 7.5 High 2026-09-15
CVE-2026-82397 Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop CWE-400 7.5 High 2026-08-31
CVE-2026-49855 tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) CWE-409 7.5 High 2026-07-14
CVE-2026-49854 Tornado: Out-of-bounds memory access in C extension CWE-126 5.3 Medium 2026-07-14
CVE-2026-49853 Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient CWE-200 7.7 High 2026-07-14
CVE-2026-35536 Tornado 安全漏洞 CWE-159 7.2 High 2026-04-03
CVE-2026-31958 Tornado has a DoS due to too many multipart parts CWE-400 6.5AI Medium AI 2026-03-11
CVE-2025-67726 Tornado is Vulnerable to Quadratic DoS via Crafted Multipart Parameters CWE-834 7.5 High 2025-12-12
CVE-2025-67725 Tornado is Vulnerable to Quadratic DoS via Repeated Header Coalescing CWE-400 7.5 High 2025-12-12
CVE-2025-67724 Tornado vulnerable to Header Injection and XSS via reason argument CWE-79 5.4 Medium 2025-12-12
CVE-2025-47287 Tornado vulnerable to excessive logging caused by malformed multipart form data CWE-770 7.5 High 2025-05-15
CVE-2024-52804 Tornado has HTTP cookie parsing DoS vulnerability CWE-400 7.5 High 2024-11-22
CVE-2023-28370 Tornado 输入验证错误漏洞 6.1 - 2023-05-25

All 18 known CVE vulnerabilities affecting Tornado with full Chinese analysis, references, and POCs where available.