{"schema_version":1,"title":"tornado (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 23 vulnerabilities in tornado (PyPI): 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-91992, was published on 15 September 2026.","url":"https://junglewise.ai/threats/technologies/tornado","json_url":"https://junglewise.ai/threats/technologies/tornado.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/tornado","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":10,"all_time":23,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":9,"last_90_days":17,"last_365_days":20},"latest":[{"cve":"CVE-2026-91992","cvss":5.9,"epss":0.0026,"slug":"cve-2026-91992-tornado-curlasynchttpclient-credential-leak-via-handle-reuse","title":"Tornado CurlAsyncHTTPClient credential leak via handle reuse","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:58.447+00:00","url":"https://junglewise.ai/threats/cve-2026-91992-tornado-curlasynchttpclient-credential-leak-via-handle-reuse"},{"cve":"CVE-2026-91991","cvss":5.4,"epss":0.0028,"slug":"cve-2026-91991-tornado-cookie-attribute-injection-via-capitalized-kwargs","title":"Tornado cookie attribute injection via capitalized kwargs","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:58.293+00:00","url":"https://junglewise.ai/threats/cve-2026-91991-tornado-cookie-attribute-injection-via-capitalized-kwargs"},{"cve":"CVE-2026-91990","cvss":7.5,"epss":0.0049,"slug":"cve-2026-91990-tornado-memory-amplification-vulnerability-in-multipart-form","title":"Tornado memory amplification vulnerability in multipart form parsing","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:58.147+00:00","url":"https://junglewise.ai/threats/cve-2026-91990-tornado-memory-amplification-vulnerability-in-multipart-form"},{"cve":"CVE-2024-58384","cvss":5.4,"epss":0.0024,"slug":"cve-2024-58384-tornado-curlasynchttpclient-crlf-injection-in-request-headers","title":"Tornado CurlAsyncHTTPClient CRLF injection in request headers","severity":"medium","exploited":false,"published_at":"2026-09-15T16:17:07.053+00:00","url":"https://junglewise.ai/threats/cve-2024-58384-tornado-curlasynchttpclient-crlf-injection-in-request-headers"},{"cve":"CVE-2024-14029","cvss":7.5,"epss":0.0035,"slug":"cve-2024-14029-tornado-http-request-smuggling-via-duplicate-transfer-encoding","title":"Tornado HTTP request smuggling via duplicate Transfer-Encoding headers","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:06.893+00:00","url":"https://junglewise.ai/threats/cve-2024-14029-tornado-http-request-smuggling-via-duplicate-transfer-encoding"},{"cve":"CVE-2023-54397","cvss":7.5,"epss":0.0037,"slug":"cve-2023-54397-tornado-http-request-smuggling-in-content-length-parsing","title":"Tornado HTTP request smuggling in Content-Length parsing","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:05.777+00:00","url":"https://junglewise.ai/threats/cve-2023-54397-tornado-http-request-smuggling-in-content-length-parsing"},{"cvss":6.9,"slug":"tornado-multipart-form-data-memory-amplification-dos-in-httputil-py-5d8eb9f2","title":"Tornado multipart form data memory amplification DoS in httputil.py","severity":"medium","exploited":false,"published_at":"2026-09-01T20:17:38+00:00","url":"https://junglewise.ai/threats/tornado-multipart-form-data-memory-amplification-dos-in-httputil-py-5d8eb9f2"},{"cvss":2.3,"slug":"tornado-cookie-attribute-injection-via-case-insensitive-kwargs-c42b886c","title":"Tornado cookie attribute injection via case-insensitive kwargs","severity":"low","exploited":false,"published_at":"2026-09-01T20:17:23+00:00","url":"https://junglewise.ai/threats/tornado-cookie-attribute-injection-via-case-insensitive-kwargs-c42b886c"},{"cve":"CVE-2026-82397","cvss":7.5,"epss":0.0063,"slug":"cve-2026-82397-tornado-urlencoded-body-parsing-dos-via-unbounded-fields","title":"Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded requ","severity":"high","exploited":false,"published_at":"2026-08-31T22:17:22.92+00:00","url":"https://junglewise.ai/threats/cve-2026-82397-tornado-urlencoded-body-parsing-dos-via-unbounded-fields"},{"cve":"CVE-2025-67726","cvss":7.5,"epss":0.0054,"slug":"cve-2025-67726-tornado-quadratic-dos-in-httputil-parseparam","title":"Tornado quadratic DoS in httputil _parseparam","severity":"high","exploited":false,"published_at":"2026-07-20T18:57:54+00:00","url":"https://junglewise.ai/threats/cve-2025-67726-tornado-quadratic-dos-in-httputil-parseparam"},{"cve":"CVE-2025-67725","cvss":7.5,"epss":0.0056,"slug":"cve-2025-67725-tornado-quadratic-dos-via-repeated-header-coalescing","title":"Tornado quadratic DoS via repeated header coalescing","severity":"high","exploited":false,"published_at":"2026-07-20T18:57:34+00:00","url":"https://junglewise.ai/threats/cve-2025-67725-tornado-quadratic-dos-via-repeated-header-coalescing"},{"cve":"CVE-2025-67724","cvss":5.4,"epss":0.0024,"slug":"cve-2025-67724-tornado-header-injection-and-xss-in-reason-argument","title":"Tornado header injection and XSS in reason argument","severity":"medium","exploited":false,"published_at":"2026-07-20T18:55:11+00:00","url":"https://junglewise.ai/threats/cve-2025-67724-tornado-header-injection-and-xss-in-reason-argument"},{"cve":"CVE-2026-49855","cvss":7.5,"epss":0.0061,"slug":"cve-2026-49855-tornado-memory-exhaustion-via-gzip-decompression-amplification","title":"Tornado memory exhaustion via gzip decompression amplification","severity":"high","exploited":false,"published_at":"2026-07-14T21:17:02.437+00:00","url":"https://junglewise.ai/threats/cve-2026-49855-tornado-memory-exhaustion-via-gzip-decompression-amplification"},{"cve":"CVE-2026-49854","cvss":5.3,"epss":0.0042,"slug":"cve-2026-49854-tornadoweb-tornado-buffer-over-read-in-tornado-speedups-extension","title":"Tornadoweb Tornado buffer over-read in tornado.speedups extension","severity":"medium","exploited":false,"published_at":"2026-07-14T21:17:02.3+00:00","url":"https://junglewise.ai/threats/cve-2026-49854-tornadoweb-tornado-buffer-over-read-in-tornado-speedups-extension"},{"cve":"CVE-2026-49853","cvss":7.7,"epss":0.0045,"slug":"cve-2026-49853-tornado-simpleasynchttpclient-sensitive-header-exposure-in","title":"Tornado SimpleAsyncHTTPClient sensitive header exposure in redirects","severity":"high","exploited":false,"published_at":"2026-07-14T21:17:02.13+00:00","url":"https://junglewise.ai/threats/cve-2026-49853-tornado-simpleasynchttpclient-sensitive-header-exposure-in"},{"cve":"CVE-2025-47287","cvss":3.1,"epss":0.0074,"slug":"cve-2025-47287-tornado-vulnerable-to-excessive-logging-caused-by-malformed","title":"PYSEC-2026-1974 - Tornado vulnerable to excessive logging caused by malformed multipart form data","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:52.554242+00:00","url":"https://junglewise.ai/threats/cve-2025-47287-tornado-vulnerable-to-excessive-logging-caused-by-malformed"},{"cve":"CVE-2024-52804","cvss":3.1,"epss":0.0104,"slug":"cve-2024-52804-tornado-has-an-http-cookie-parsing-dos-vulnerability","title":"PYSEC-2026-1975 - Tornado has an HTTP cookie parsing DoS vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:45.585102+00:00","url":"https://junglewise.ai/threats/cve-2024-52804-tornado-has-an-http-cookie-parsing-dos-vulnerability"},{"cvss":5.9,"slug":"tornado-curlasynchttpclient-credential-leak-on-handle-reuse-ff5043d2","title":"Tornado CurlAsyncHTTPClient credential leak on handle reuse","severity":"medium","exploited":false,"published_at":"2026-06-15T20:37:24+00:00","url":"https://junglewise.ai/threats/tornado-curlasynchttpclient-credential-leak-on-handle-reuse-ff5043d2"},{"cve":"CVE-2026-35536","cvss":7.2,"epss":0.0029,"slug":"cve-2026-35536-tornado-cookie-attribute-injection-in-requesthandler-set-cookie","title":"Tornado cookie attribute injection in RequestHandler.set_cookie","severity":"high","exploited":false,"published_at":"2026-04-03T04:16:53.55+00:00","url":"https://junglewise.ai/threats/cve-2026-35536-tornado-cookie-attribute-injection-in-requesthandler-set-cookie"},{"cve":"CVE-2026-31958","cvss":7.5,"epss":0.0049,"slug":"cve-2026-31958-tornado-denial-of-service-in-multipart-form-parsing","title":"Tornado denial of service in multipart form parsing","severity":"high","exploited":false,"published_at":"2026-03-12T14:19:52+00:00","url":"https://junglewise.ai/threats/cve-2026-31958-tornado-denial-of-service-in-multipart-form-parsing"},{"cve":"CVE-2023-28370","cvss":3.1,"epss":0.0114,"slug":"cve-2023-28370-open-redirect-in-tornado","title":"PYSEC-2023-75 - Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrar","severity":"low","exploited":false,"published_at":"2023-05-25T10:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-28370-open-redirect-in-tornado"},{"cve":"CVE-2014-9720","cvss":3.1,"epss":0.0251,"slug":"cve-2014-9720-tornado-xsrf-cookie-allows-side-channel-attack-against-tls-breach","title":"PYSEC-2020-213 - Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier","severity":"low","exploited":false,"published_at":"2020-01-24T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2014-9720-tornado-xsrf-cookie-allows-side-channel-attack-against-tls-breach"},{"cve":"CVE-2012-2374","cvss":3.1,"epss":0.0137,"slug":"cve-2012-2374-tornado-crlf-injection-vulnerability","title":"PYSEC-2012-5 - CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject","severity":"low","exploited":false,"published_at":"2012-05-23T20:55:00+00:00","url":"https://junglewise.ai/threats/cve-2012-2374-tornado-crlf-injection-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"tornado (PyPI)","slug":"tornado","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://www.tornadoweb.org/","repo_url":"https://github.com/tornadoweb/tornado","description":"A Python web framework and asynchronous networking library designed to handle long-lived connections.","url":"https://junglewise.ai/threats/technologies/tornado"},"most_severe":[{"cve":"CVE-2026-49853","cvss":7.7,"epss":0.0045,"slug":"cve-2026-49853-tornado-simpleasynchttpclient-sensitive-header-exposure-in","title":"Tornado SimpleAsyncHTTPClient sensitive header exposure in redirects","severity":"high","exploited":false,"published_at":"2026-07-14T21:17:02.13+00:00","url":"https://junglewise.ai/threats/cve-2026-49853-tornado-simpleasynchttpclient-sensitive-header-exposure-in"},{"cve":"CVE-2026-82397","cvss":7.5,"epss":0.0063,"slug":"cve-2026-82397-tornado-urlencoded-body-parsing-dos-via-unbounded-fields","title":"Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded requ","severity":"high","exploited":false,"published_at":"2026-08-31T22:17:22.92+00:00","url":"https://junglewise.ai/threats/cve-2026-82397-tornado-urlencoded-body-parsing-dos-via-unbounded-fields"},{"cve":"CVE-2026-49855","cvss":7.5,"epss":0.0061,"slug":"cve-2026-49855-tornado-memory-exhaustion-via-gzip-decompression-amplification","title":"Tornado memory exhaustion via gzip decompression amplification","severity":"high","exploited":false,"published_at":"2026-07-14T21:17:02.437+00:00","url":"https://junglewise.ai/threats/cve-2026-49855-tornado-memory-exhaustion-via-gzip-decompression-amplification"},{"cve":"CVE-2025-67725","cvss":7.5,"epss":0.0056,"slug":"cve-2025-67725-tornado-quadratic-dos-via-repeated-header-coalescing","title":"Tornado quadratic DoS via repeated header coalescing","severity":"high","exploited":false,"published_at":"2026-07-20T18:57:34+00:00","url":"https://junglewise.ai/threats/cve-2025-67725-tornado-quadratic-dos-via-repeated-header-coalescing"},{"cve":"CVE-2025-67726","cvss":7.5,"epss":0.0054,"slug":"cve-2025-67726-tornado-quadratic-dos-in-httputil-parseparam","title":"Tornado quadratic DoS in httputil _parseparam","severity":"high","exploited":false,"published_at":"2026-07-20T18:57:54+00:00","url":"https://junglewise.ai/threats/cve-2025-67726-tornado-quadratic-dos-in-httputil-parseparam"},{"cve":"CVE-2026-91990","cvss":7.5,"epss":0.0049,"slug":"cve-2026-91990-tornado-memory-amplification-vulnerability-in-multipart-form","title":"Tornado memory amplification vulnerability in multipart form parsing","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:58.147+00:00","url":"https://junglewise.ai/threats/cve-2026-91990-tornado-memory-amplification-vulnerability-in-multipart-form"},{"cve":"CVE-2026-31958","cvss":7.5,"epss":0.0049,"slug":"cve-2026-31958-tornado-denial-of-service-in-multipart-form-parsing","title":"Tornado denial of service in multipart form parsing","severity":"high","exploited":false,"published_at":"2026-03-12T14:19:52+00:00","url":"https://junglewise.ai/threats/cve-2026-31958-tornado-denial-of-service-in-multipart-form-parsing"},{"cve":"CVE-2023-54397","cvss":7.5,"epss":0.0037,"slug":"cve-2023-54397-tornado-http-request-smuggling-in-content-length-parsing","title":"Tornado HTTP request smuggling in Content-Length parsing","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:05.777+00:00","url":"https://junglewise.ai/threats/cve-2023-54397-tornado-http-request-smuggling-in-content-length-parsing"},{"cve":"CVE-2024-14029","cvss":7.5,"epss":0.0035,"slug":"cve-2024-14029-tornado-http-request-smuggling-via-duplicate-transfer-encoding","title":"Tornado HTTP request smuggling via duplicate Transfer-Encoding headers","severity":"high","exploited":false,"published_at":"2026-09-15T16:17:06.893+00:00","url":"https://junglewise.ai/threats/cve-2024-14029-tornado-http-request-smuggling-via-duplicate-transfer-encoding"},{"cve":"CVE-2026-35536","cvss":7.2,"epss":0.0029,"slug":"cve-2026-35536-tornado-cookie-attribute-injection-in-requesthandler-set-cookie","title":"Tornado cookie attribute injection in RequestHandler.set_cookie","severity":"high","exploited":false,"published_at":"2026-04-03T04:16:53.55+00:00","url":"https://junglewise.ai/threats/cve-2026-35536-tornado-cookie-attribute-injection-in-requesthandler-set-cookie"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}