35 Total advisories
35 Vulnerabilities
0 Malware

Dependency scanning

Check whether tornado is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.5
PyPI

CVE-2024-58384

Tornado has a CRLF injection in CurlAsyncHTTPClient headers

MEDIUM 5.3
PyPI

CVE-2024-14029

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

UNKNOWN
PyPI

CVE-2026-91990

tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)

UNKNOWN
PyPI

CVE-2023-54397

Tornado vulnerable to HTTP request smuggling via improper parsing of `Content-Length` fields and chunk lengths

MEDIUM 5.9
PyPI

CVE-2026-91992

Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

UNKNOWN
PyPI

CVE-2026-91991

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

HIGH 7.5
PyPI

CVE-2026-82397

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

HIGH 7.5
PyPI

CVE-2026-82397

Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop

HIGH 7.5
PyPI

CVE-2026-49855

tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

HIGH 7.7
PyPI

CVE-2026-49853

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

LOW 3.7
PyPI

CVE-2026-49854

Tornado has out-of-bounds memory access via C extension

HIGH 7.2
PyPI

CVE-2026-35536

Tornado has cookie attribute injection via .RequestHandler.set_cookie

HIGH 7.5
PyPI

CVE-2026-31958

Tornado is vulnerable to DoS due to too many multipart parts

MEDIUM 5.4
PyPI

CVE-2026-35536

Tornado has incomplete validation of cookie attributes

HIGH 7.5
PyPI

CVE-2025-47287

Tornado vulnerable to excessive logging caused by malformed multipart form data

HIGH 7.5
PyPI

CVE-2024-52804

Tornado has an HTTP cookie parsing DoS vulnerability

HIGH 7.5
PyPI

CVE-2025-67726

Tornado: Quadratic DoS via Crafted Multipart Parameters

HIGH 7.5
PyPI

CVE-2025-67725

Tornado: Quadratic DoS via Repeated Header Coalescing

MEDIUM 5.4
PyPI

CVE-2025-67724

Tornado vulnerable to Header Injection and XSS via reason argument

MEDIUM 5.3
PyPI

CVE-2026-35536

CVE-2026-35536

HIGH 7.5
PyPI

CVE-2026-49855

tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

LOW 3.7
PyPI

CVE-2026-49854

Tornado has out-of-bounds memory access via C extension

HIGH 7.7
PyPI

CVE-2026-49853

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

HIGH 7.5
PyPI

CVE-2025-67726

CVE-2025-67726

MEDIUM 6.1
PyPI

CVE-2025-67724

CVE-2025-67724

HIGH 7.5
PyPI

CVE-2025-67725

CVE-2025-67725

HIGH 7.5
PyPI

CVE-2025-47287

Tornado vulnerable to excessive logging caused by malformed multipart form data

HIGH 7.5
PyPI

CVE-2024-52804

Tornado has an HTTP cookie parsing DoS vulnerability

UNKNOWN
PyPI

CVE-2014-9720

CVE-2014-9720

UNKNOWN
PyPI

CVE-2023-28370

CVE-2023-28370

UNKNOWN
PyPI

CVE-2012-2374

CVE-2012-2374

HIGH 7.5
PyPI

CVE-2026-31958

CVE-2026-31958

MEDIUM 6.1
PyPI

CVE-2023-28370

Open redirect in Tornado

HIGH 7.5
PyPI

CVE-2012-2374

Tornado CRLF injection vulnerability

MEDIUM 6.5
PyPI

CVE-2014-9720

Tornado XSRF cookie allows side-channel attack against TLS (BREACH attack)

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes