Dependency scanning
Check whether tornado is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-58384
Tornado has a CRLF injection in CurlAsyncHTTPClient headers
CVE-2024-14029
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado
CVE-2026-91990
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
CVE-2023-54397
Tornado vulnerable to HTTP request smuggling via improper parsing of `Content-Length` fields and chunk lengths
CVE-2026-91992
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
CVE-2026-91991
Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`
CVE-2026-82397
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
CVE-2026-82397
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
CVE-2026-49855
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
CVE-2026-49853
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
CVE-2026-49854
Tornado has out-of-bounds memory access via C extension
CVE-2026-35536
Tornado has cookie attribute injection via .RequestHandler.set_cookie
CVE-2026-31958
Tornado is vulnerable to DoS due to too many multipart parts
CVE-2026-35536
Tornado has incomplete validation of cookie attributes
CVE-2025-47287
Tornado vulnerable to excessive logging caused by malformed multipart form data
CVE-2024-52804
Tornado has an HTTP cookie parsing DoS vulnerability
CVE-2025-67726
Tornado: Quadratic DoS via Crafted Multipart Parameters
CVE-2025-67725
Tornado: Quadratic DoS via Repeated Header Coalescing
CVE-2025-67724
Tornado vulnerable to Header Injection and XSS via reason argument
CVE-2026-35536
CVE-2026-35536
CVE-2026-49855
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
CVE-2026-49854
Tornado has out-of-bounds memory access via C extension
CVE-2026-49853
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
CVE-2025-67726
CVE-2025-67726
CVE-2025-67724
CVE-2025-67724
CVE-2025-67725
CVE-2025-67725
CVE-2025-47287
Tornado vulnerable to excessive logging caused by malformed multipart form data
CVE-2024-52804
Tornado has an HTTP cookie parsing DoS vulnerability
CVE-2014-9720
CVE-2014-9720
CVE-2023-28370
CVE-2023-28370
CVE-2012-2374
CVE-2012-2374
CVE-2026-31958
CVE-2026-31958
CVE-2023-28370
Open redirect in Tornado
CVE-2012-2374
Tornado CRLF injection vulnerability
CVE-2014-9720
Tornado XSRF cookie allows side-channel attack against TLS (BREACH attack)
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes