Linuxsecurity Critical DoS Vulnerabilities in Python-Tornado Affecting SUSE and Debian
Article Content
- •CVE-2025-67725 and CVE-2026-31958 pose critical DoS risks to Python-Tornado users.
- •SUSE and Debian have issued patches to fix these vulnerabilities as of April 1, 2026.
- •Incomplete cookie attribute validation could lead to further security issues.
Two significant vulnerabilities in the Python-Tornado framework have been disclosed, impacting SUSE 12 and Debian 11 systems. CVE-2025-67725 allows for Denial of Service (DoS) via maliciously crafted HTTP requests, while CVE-2026-31958 introduces risks from parsing large multipart bodies, potentially leading to DoS attacks. Both vulnerabilities have been assigned high CVSS scores, with CVE-2025-67725 rated at 8.7. Additionally, there are concerns regarding incomplete validation of cookie attributes, which could lead to further exploitation. Users are advised to apply the latest patches immediately to mitigate these risks. The vulnerabilities were published in December 2025 and March 2026, respectively. Both SUSE and Debian have released updates to address these issues. Failure to patch could leave systems vulnerable to exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Debian and CVE-2025-67724 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…