Package compatibility

Tornado

Python requirements from PyPI (requires_python / classifiers) for the tornado package. This is not a lifecycle software page.

Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.

Version lines

Each line reflects a declared requires_python tip. Requirement changes across tips appear as separate lines when present.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2025-67726GHSA-jhmp-mqwm-3gq8

    Tornado: Quadratic DoS via Crafted Multipart Parameters

    Affected:
    <6.5.3
    Fixed in:
    6.5.3
    Source:
    OSV source · Advisory
  • CVE-2025-67725GHSA-c98p-7wgm-6p64

    Tornado: Quadratic DoS via Repeated Header Coalescing

    Affected:
    <6.5.3
    Fixed in:
    6.5.3
    Source:
    OSV source · Advisory
  • CVE-2025-67724GHSA-pr2v-jx2c-wg9f

    Tornado vulnerable to Header Injection and XSS via reason argument

    Affected:
    <6.5.3
    Fixed in:
    6.5.3
    Source:
    OSV source · Advisory
  • CVE-2026-49853PYSEC-2026-3387

    Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source · Advisory
  • CVE-2026-49855PYSEC-2026-3389

    tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source · Advisory
  • CVE-2026-49854PYSEC-2026-3388

    Tornado has out-of-bounds memory access via C extension

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source · Advisory
  • CVE-2025-47287PYSEC-2026-1974

    Tornado vulnerable to excessive logging caused by malformed multipart form data

    Affected:
    <6.5
    Fixed in:
    6.5
    Source:
    OSV source · Advisory
  • CVE-2024-52804PYSEC-2026-1975

    Tornado has an HTTP cookie parsing DoS vulnerability

    Affected:
    <6.4.2
    Fixed in:
    6.4.2
    Source:
    OSV source · Advisory
  • GHSA-pw6j-qg29-8w7f

    Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

    Affected:
    <6.5.7
    Fixed in:
    6.5.7
    Source:
    OSV source
  • CVE-2026-49853GHSA-3x9g-8vmp-wqvf

    Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source
  • CVE-2026-49855GHSA-mgf9-4vpg-hj56

    tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source
  • CVE-2026-49854GHSA-cx3h-4qpv-8hc9

    Tornado has out-of-bounds memory access via C extension

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source