Technology · PyPI
tornado (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 23 vulnerabilities in tornado (PyPI): 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91992, was published on 15 September 2026.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 0
- Exploited in the wild
- 0
About tornado (PyPI)
A Python web framework and asynchronous networking library designed to handle long-lived connections.
Latest tornado (PyPI) vulnerabilities
- CVE-2026-91992: Tornado CurlAsyncHTTPClient credential leak via handle reusemediumCVSS 5.9EPSS 0.3%
- CVE-2026-91991: Tornado cookie attribute injection via capitalized kwargsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-91990: Tornado memory amplification vulnerability in multipart form parsinghighCVSS 7.5EPSS 0.5%
- CVE-2024-58384: Tornado CurlAsyncHTTPClient CRLF injection in request headersmediumCVSS 5.4EPSS 0.2%
- CVE-2024-14029: Tornado HTTP request smuggling via duplicate Transfer-Encoding headershighCVSS 7.5EPSS 0.4%
- CVE-2023-54397: Tornado HTTP request smuggling in Content-Length parsinghighCVSS 7.5EPSS 0.4%
- Tornado multipart form data memory amplification DoS in httputil.pymediumCVSS 6.9
- Tornado cookie attribute injection via case-insensitive kwargslowCVSS 2.3
- CVE-2026-82397: Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses…highCVSS 7.5EPSS 0.6%
- CVE-2025-67726: Tornado quadratic DoS in httputil _parseparamhighCVSS 7.5EPSS 0.5%
- CVE-2025-67725: Tornado quadratic DoS via repeated header coalescinghighCVSS 7.5EPSS 0.6%
- CVE-2025-67724: Tornado header injection and XSS in reason argumentmediumCVSS 5.4EPSS 0.2%
- CVE-2026-49855: Tornado memory exhaustion via gzip decompression amplificationhighCVSS 7.5EPSS 0.6%
- CVE-2026-49854: Tornadoweb Tornado buffer over-read in tornado.speedups extensionmediumCVSS 5.3EPSS 0.4%
- CVE-2026-49853: Tornado SimpleAsyncHTTPClient sensitive header exposure in redirectshighCVSS 7.7EPSS 0.4%
- CVE-2025-47287: PYSEC-2026-1974 - Tornado vulnerable to excessive logging caused by malformed multipart form datalowCVSS 3.1EPSS 0.7%
- CVE-2024-52804: PYSEC-2026-1975 - Tornado has an HTTP cookie parsing DoS vulnerabilitylowCVSS 3.1EPSS 1.0%
- Tornado CurlAsyncHTTPClient credential leak on handle reusemediumCVSS 5.9
- CVE-2026-35536: Tornado cookie attribute injection in RequestHandler.set_cookiehighCVSS 7.2EPSS 0.3%
- CVE-2026-31958: Tornado denial of service in multipart form parsinghighCVSS 7.5EPSS 0.5%
- CVE-2023-28370: PYSEC-2023-75 - Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker…lowCVSS 3.1EPSS 1.1%
- CVE-2014-9720: PYSEC-2020-213 - Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP…lowCVSS 3.1EPSS 2.5%
- CVE-2012-2374: PYSEC-2012-5 - CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1…lowCVSS 3.1EPSS 1.4%
Most severe tornado (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-49853: Tornado SimpleAsyncHTTPClient sensitive header exposure in redirectshighCVSS 7.7EPSS 0.4%
- CVE-2026-82397: Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses…highCVSS 7.5EPSS 0.6%
- CVE-2026-49855: Tornado memory exhaustion via gzip decompression amplificationhighCVSS 7.5EPSS 0.6%
- CVE-2025-67725: Tornado quadratic DoS via repeated header coalescinghighCVSS 7.5EPSS 0.6%
- CVE-2025-67726: Tornado quadratic DoS in httputil _parseparamhighCVSS 7.5EPSS 0.5%
- CVE-2026-91990: Tornado memory amplification vulnerability in multipart form parsinghighCVSS 7.5EPSS 0.5%
- CVE-2026-31958: Tornado denial of service in multipart form parsinghighCVSS 7.5EPSS 0.5%
- CVE-2023-54397: Tornado HTTP request smuggling in Content-Length parsinghighCVSS 7.5EPSS 0.4%
- CVE-2024-14029: Tornado HTTP request smuggling via duplicate Transfer-Encoding headershighCVSS 7.5EPSS 0.4%
- CVE-2026-35536: Tornado cookie attribute injection in RequestHandler.set_cookiehighCVSS 7.2EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 3 | 0 | |
| 20 Jul 2026 | 3 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 3 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 6 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/tornado.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "tornado (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/tornado, 26 September 2026.