Back Linuxsecurity Debian 11 python-tornado Critical Custom Phrases DoS CVE-2025
CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, ...) due to being used unescaped in HTTP headers. CVE-2025-67725 A single maliciously crafted HTTP request can cause a possible DoS due to quadratic performance of repeated header lines. CVE-2025-67726 An inefficient algorithm when parsing parameters for HTTP header values can potentially cause a DoS. For Debian 11 bullseye, these problems have been fixed in version 6.1.0-1+deb11u3. We recommend that you upgrade your python-tornado packages. For the detailed security status of python-tornado please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, ...) due to being used unescaped in HTTP headers. CVE-2025-67725 A single maliciously crafted HTTP request can cause a possible DoS due to quadratic performance of repeated header lines. CVE-2025-67726 An inefficient algorithm when parsing parameters for HTTP header values can potentially cause a DoS. For Debian 11 bullseye, these problems have been fixed in version 6.1.0-1+deb11u3. We recommend that you upgrade your python-tornado packages. For the detailed security status of python-tornado please refer to its security tracker page at: Further information Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
