Package compatibility
Tornado
Python requirements from PyPI (requires_python / classifiers) for the tornado package. This is not a lifecycle software page.
Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.
Version lines
Each line reflects a declared requires_python tip. Requirement changes across tips appear as separate lines when present.
Tornado 6.0
tip 6.0.4Python >=3.5,<3.9
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Tornado 6.1
tip 6.1Python >=3.5,<3.10
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Tornado 6.2
tip 6.2Python >=3.7,<3.11
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Tornado 6.3
tip 6.3.3Python >=3.8,<3.12
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Tornado 6.4
tip 6.4.2Python >=3.8,<3.12
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Tornado 6.5
tip 6.5.8Python >=3.9,<3.14
Source: package metadata
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2025-67726GHSA-jhmp-mqwm-3gq8
Tornado: Quadratic DoS via Crafted Multipart Parameters
- Affected:
- <6.5.3
- Fixed in:
- 6.5.3
- Source:
- OSV source · Advisory
- CVE-2025-67725GHSA-c98p-7wgm-6p64
Tornado: Quadratic DoS via Repeated Header Coalescing
- Affected:
- <6.5.3
- Fixed in:
- 6.5.3
- Source:
- OSV source · Advisory
- CVE-2025-67724GHSA-pr2v-jx2c-wg9f
Tornado vulnerable to Header Injection and XSS via reason argument
- Affected:
- <6.5.3
- Fixed in:
- 6.5.3
- Source:
- OSV source · Advisory
- CVE-2026-49853PYSEC-2026-3387
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source · Advisory
- CVE-2026-49855PYSEC-2026-3389
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source · Advisory
- CVE-2026-49854PYSEC-2026-3388
Tornado has out-of-bounds memory access via C extension
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source · Advisory
- CVE-2025-47287PYSEC-2026-1974
Tornado vulnerable to excessive logging caused by malformed multipart form data
- Affected:
- <6.5
- Fixed in:
- 6.5
- Source:
- OSV source · Advisory
- CVE-2024-52804PYSEC-2026-1975
Tornado has an HTTP cookie parsing DoS vulnerability
- Affected:
- <6.4.2
- Fixed in:
- 6.4.2
- Source:
- OSV source · Advisory
- GHSA-pw6j-qg29-8w7f
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
- Affected:
- <6.5.7
- Fixed in:
- 6.5.7
- Source:
- OSV source
- CVE-2026-49853GHSA-3x9g-8vmp-wqvf
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source
- CVE-2026-49855GHSA-mgf9-4vpg-hj56
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source
- CVE-2026-49854GHSA-cx3h-4qpv-8hc9
Tornado has out-of-bounds memory access via C extension
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source
