tornadoweb records
10 published records for vendor tornadoweb.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption4
- CWE-20 Improper Input Validation1
- CWE-203 Observable Discrepancy1
- CWE-159 Improper Handling of Invalid Use of Special Elements1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2026-31958No exploit | Tornado has a DoS due to too many multipart partstornadoweb · tornado · CWE-400 | High8.7 | — | 0.5% | Mar 11, 2026 |
30Monitor | CVE-2024-52804No exploit | Tornado has HTTP cookie parsing DoS vulnerabilitytornadoweb · tornado · CWE-400 | High7.5 | — | 1.0% | Nov 22, 2024 |
30Monitor | CVE-2025-47287No exploit | Tornado vulnerable to excessive logging caused by malformed multipart form datatornadoweb · tornado · CWE-770 | High7.5 | — | 0.7% | May 15, 2025 |
30Monitor | CVE-2025-67725No exploit | Tornado is Vulnerable to Quadratic DoS via Repeated Header Coalescingtornadoweb · tornado · CWE-400 | High7.5 | — | 0.6% | Dec 12, 2025 |
30Monitor | CVE-2025-67726No exploit | Tornado is Vulnerable to Quadratic DoS via Crafted Multipart Parameterstornadoweb · tornado · CWE-400 | High7.5 | — | 0.5% | Dec 12, 2025 |
27Monitor | CVE-2014-9720No exploit | Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier tornadoweb · tornado · CWE-203 | Medium6.5 | — | 2.5% | Jan 24, 2020 |
24Monitor | CVE-2023-28370No exploit | Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrartornadoweb · tornado · CWE-601 | Medium6.1 | — | 1.1% | May 25, 2023 |
24Monitor | CVE-2025-67724No exploit | Tornado vulnerable to Header Injection and XSS via reason argumenttornadoweb · tornado · CWE-79 | Medium6.1 | — | 0.2% | Dec 12, 2025 |
21Monitor | CVE-2026-35536No exploit | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cooktornadoweb · tornado · CWE-159 | Medium5.3 | — | 0.3% | Apr 3, 2026 |
20Monitor | CVE-2012-2374No exploit | CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to injecttornadoweb · tornado · CWE-20 | Medium5.0 | — | 1.4% | May 23, 2012 |
- CVE-2026-3195834Monitor
Tornado has a DoS due to too many multipart parts
HighCVSS 8.7No exploitEPSS 0%tornadoweb · tornadoMar 11, 2026
- CVE-2024-5280430Monitor
Tornado has HTTP cookie parsing DoS vulnerability
HighCVSS 7.5No exploitEPSS 1%tornadoweb · tornadoNov 22, 2024
- CVE-2025-4728730Monitor
Tornado vulnerable to excessive logging caused by malformed multipart form data
HighCVSS 7.5No exploitEPSS 1%tornadoweb · tornadoMay 15, 2025
- CVE-2025-6772530Monitor
Tornado is Vulnerable to Quadratic DoS via Repeated Header Coalescing
HighCVSS 7.5No exploitEPSS 1%tornadoweb · tornadoDec 12, 2025
- CVE-2025-6772630Monitor
Tornado is Vulnerable to Quadratic DoS via Crafted Multipart Parameters
HighCVSS 7.5No exploitEPSS 1%tornadoweb · tornadoDec 12, 2025
- CVE-2014-972027Monitor
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier
MediumCVSS 6.5No exploitEPSS 3%tornadoweb · tornadoJan 24, 2020
- CVE-2023-2837024Monitor
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrar
MediumCVSS 6.1No exploitEPSS 1%tornadoweb · tornadoMay 25, 2023
- CVE-2025-6772424Monitor
Tornado vulnerable to Header Injection and XSS via reason argument
MediumCVSS 6.1No exploitEPSS 0%tornadoweb · tornadoDec 12, 2025
- CVE-2026-3553621Monitor
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cook
MediumCVSS 5.3No exploitEPSS 0%tornadoweb · tornadoApr 3, 2026
- CVE-2012-237420Monitor
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject
MediumCVSS 5.0No exploitEPSS 1%tornadoweb · tornadoMay 23, 2012