CVE Tools

Tornado

32 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Tornado, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Tornado CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Tornado CVEs per month
MonthCVEs
2024-100
2024-112
2024-120
2025-010
2025-020
2025-031
2025-040
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-123
2026-010
2026-020
2026-032
2026-041
2026-050
2026-061
2026-073
2026-081
2026-098

Severity

How the 32 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical14%
  • High1560%
  • Medium936%

Latest CVEs

The 15 most recently published vulnerabilities affecting Tornado.

  1. CVE-2026-91992Tornado before 6.5.7 Credential Leak via Handle Reuse5.9
  2. CVE-2026-91991Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs5.4
  3. CVE-2026-91990Tornado before 6.5.8 Memory Amplification DoS via multipart7.5
  4. CVE-2024-58384Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient5.4
  5. CVE-2024-14029Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding7.5
  6. CVE-2023-54397Tornado before 6.3.3 HTTP Request Smuggling via Content-Length7.5
  7. GHSA-8423-8fgw-73vqtornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)—
  8. GHSA-wwv5-g3v4-889xTornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`—
  9. CVE-2026-82397Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop7.5
  10. CVE-2026-49855tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)7.5
  11. CVE-2026-49854Tornado: Out-of-bounds memory access in C extension5.3
  12. CVE-2026-49853Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient7.7
  13. GHSA-pw6j-qg29-8w7fTornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse—
  14. CVE-2026-35536In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.7.2
  15. GHSA-78cv-mqj4-43f7Tornado has incomplete validation of cookie attributes—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store