Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Two significant vulnerabilities in the Python-Tornado framework have been disclosed, impacting SUSE 12 and Debian 11 systems. CVE-2025-67725 allows for Denial of Service (DoS) via maliciously crafted HTTP requests, while CVE-2026-31958 introduces risks from parsing large multipart bodies, potentiall...
Tornado, a web server and tools package, has critical vulnerabilities affecting multiple Ubuntu versions including 20.04 LTS, 22.04 LTS, 24.04 LTS, 25.04, and 25.10. The vulnerabilities allow attackers to execute cross-site scripting (XSS) attacks and potentially cause denial of service (DoS) by exp...
SUSE and Ubuntu have released updates for python-tornado6 to address multiple vulnerabilities, including CVE-2025-67724, which allows for header injection or XSS attacks, and CVE-2025-67725, which can lead to a Denial of Service (DoS) due to quadratic complexity in string operations. These vulnerabi...
openSUSE has released an advisory regarding critical vulnerabilities in python-tornado6 affecting HTTP headers and error pages. The vulnerabilities include potential header injection and XSS attacks (CVE-2025-67724) and a DoS risk due to quadratic complexity in string operations (CVE-2025-67725). Us...