Linuxsecurity
Critical XSS and DoS Vulnerabilities in Tornado Affect Multiple Ubuntu Releases
First seen 9 Jan 2026, 03:52 UTC
•
•88% similarity
•44.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Tornado, a web server and tools package, has critical vulnerabilities affecting multiple Ubuntu versions including 20.04 LTS, 22.04 LTS, 24.04 LTS, 25.04, and 25.10. The vulnerabilities allow attackers to execute cross-site scripting (XSS) attacks and potentially cause denial of service (DoS) by exploiting improper handling of HTTP headers. The identified CVE is CVE-2025-67724.
ThreatCluster AI