Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
Tornado Number Of NVD 4 CRITICAL 0 HIGH 0 MEDIUM 4 LOW 0
URL https://www.tornadoweb.org/
Explanation A Python web framework and asynchronous network library developed by FriendFeed.
Using non-blocking network I/O, it can scale to tens of thousands of open connections, making it ideal for long polling, WebSockets, and other applications that require long connections to each user.
It is very fast, making it ideal for applications that need to handle a large number of simultaneous connections.
Tag
  • Python
  • Apache License v2.0

Add Information URL
No Type Name URL
1 https://www.tornadoweb.org/en/stable/releases.html
2 https://github.com/tornadoweb/tornado

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1 Tornado 6 6.5.5 March 10, 2026 March 1, 2019 0 0 2 0
2 tornado 5 5.1.1 Sept. 16, 2018 March 5, 2018 0 0 2 0
3 tornado 4 4.5.3 June 6, 2018 July 15, 2014 0 0 2 0
4 tornado 3 3.2.2 June 3, 2014 March 29, 2013 0 0 3 0
5 tornado 2 2.4.1 Nov. 24, 2012 June 21, 2011 0 0 4 0
6 tornado 1 1.2.1 March 3, 2011 July 22, 2010 0 0 4 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1 5.3
-
MEDIUM
Network
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters. CWE-159
 Improper Handling of Invalid Use of Special Elements
CVE-2026-35536 cpe:2.3:a:tornadoweb:tornado:*:* 6.5.5 2026-04-11 00:14
2026-04-3
Show GitHub Exploit DB Packet Storm
2 6.1
-
MEDIUM
Network
Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user acc… CWE-601
Open Redirect
CVE-2023-28370 cpe:2.3:a:tornadoweb:tornado:*:* 6.3.2 2024-11-21 16:54
2023-05-25
Show GitHub Exploit DB Packet Storm
3 6.5
4.3
MEDIUM
Network
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determi… CWE-203
 Information Exposure Through Discrepancy
CVE-2014-9720 cpe:2.3:a:tornadoweb:tornado:*:* 3.2.2 2024-11-21 11:21
2020-01-25
Show GitHub Exploit DB Packet Storm
4 -
5.0
MEDIUM CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting… CWE-20
 Improper Input Validation 
CVE-2012-2374 cpe:2.3:a:tornadoweb:tornado:2.1:*
cpe:2.3:a:tornadoweb:tornado:2.1.1:*
cpe:2.3:a:tornadoweb:tornado:2.0:*
cpe…
2.2 2024-11-21 10:38
2012-05-24
Show GitHub Exploit DB Packet Storm