Linuxsecurity Critical DoS Vulnerabilities in Python-Tornado Affecting SUSE and Debian
Article Content
- •CVE-2025-67725 and CVE-2026-31958 pose critical DoS risks to Python-Tornado users.
- •SUSE and Debian have issued patches to fix these vulnerabilities as of April 1, 2026.
- •Incomplete cookie attribute validation could lead to further security issues.
Two significant vulnerabilities in the Python-Tornado framework have been disclosed, impacting SUSE 12 and Debian 11 systems. CVE-2025-67725 allows for Denial of Service (DoS) via maliciously crafted HTTP requests, while CVE-2026-31958 introduces risks from parsing large multipart bodies, potentially leading to DoS attacks. Both vulnerabilities have been assigned high CVSS scores, with CVE-2025-67725 rated at 8.7. Additionally, there are concerns regarding incomplete validation of cookie attributes, which could lead to further exploitation. Users are advised to apply the latest patches immediately to mitigate these risks. The vulnerabilities were published in December 2025 and March 2026, respectively. Both SUSE and Debian have released updates to address these issues. Failure to patch could leave systems vulnerable to exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Debian and CVE-2025-67724 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…