Package compatibility
Tornado 6.0
What Python versions does this Tornado version support?
Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.
Declared Python requirement
- requires_python
- >=3.5,<3.9
- Tip version
- 6.0.4
- Source
- PyPI (requires_python / classifiers)
Python compatibility matrix
Evaluated against CompatHub Python VersionLines. Compatibility and lifecycle status are separate signals.
- Python 2.6 line →
- Python 2.7 line →
- Python 3.0 line →
- Python 3.1 line →
- Python 3.2 line →
- Python 3.3 line →
- Python 3.4 line →
- Python 3.5 line →
- Python 3.6 line →
- Python 3.7 line →
- Python 3.8 line →
- Python 3.9 line →
- Python 3.10 line →
- Python 3.11 line →
- Python 3.12 line →
- Python 3.13 line →
- Python 3.14 line →
- Python 3.15 line →
- Python 3.16 line →
Other Tornado lines
Security
Advisories affecting Tornado 6.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.
- Known vulnerabilities
- 15
- Known exploited
- 0
- Highest CVSS
- —
- CVE-2025-67726GHSA-jhmp-mqwm-3gq8
Tornado: Quadratic DoS via Crafted Multipart Parameters
- Affected:
- <6.5.3
- Fixed in:
- 6.5.3
- Source:
- OSV source · Advisory
- CVE-2025-67725GHSA-c98p-7wgm-6p64
Tornado: Quadratic DoS via Repeated Header Coalescing
- Affected:
- <6.5.3
- Fixed in:
- 6.5.3
- Source:
- OSV source · Advisory
- CVE-2025-67724GHSA-pr2v-jx2c-wg9f
Tornado vulnerable to Header Injection and XSS via reason argument
- Affected:
- <6.5.3
- Fixed in:
- 6.5.3
- Source:
- OSV source · Advisory
- CVE-2026-49853PYSEC-2026-3387
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source · Advisory
- CVE-2026-49855PYSEC-2026-3389
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source · Advisory
- CVE-2026-49854PYSEC-2026-3388
Tornado has out-of-bounds memory access via C extension
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source · Advisory
- CVE-2025-47287PYSEC-2026-1974
Tornado vulnerable to excessive logging caused by malformed multipart form data
- Affected:
- <6.5
- Fixed in:
- 6.5
- Source:
- OSV source · Advisory
- CVE-2024-52804PYSEC-2026-1975
Tornado has an HTTP cookie parsing DoS vulnerability
- Affected:
- <6.4.2
- Fixed in:
- 6.4.2
- Source:
- OSV source · Advisory
- GHSA-pw6j-qg29-8w7f
Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
- Affected:
- <6.5.7
- Fixed in:
- 6.5.7
- Source:
- OSV source
- CVE-2026-49853GHSA-3x9g-8vmp-wqvf
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source
- CVE-2026-49855GHSA-mgf9-4vpg-hj56
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source
- CVE-2026-49854GHSA-cx3h-4qpv-8hc9
Tornado has out-of-bounds memory access via C extension
- Affected:
- <6.5.6
- Fixed in:
- 6.5.6
- Source:
- OSV source
- CVE-2026-35536GHSA-fqwm-6jpj-5wxc
Tornado has cookie attribute injection via .RequestHandler.set_cookie
- Affected:
- <6.5.5
- Fixed in:
- 6.5.5
- Source:
- OSV source · Advisory
- CVE-2026-35536PYSEC-2026-2287
- Affected:
- <6.5.5
- Fixed in:
- 6.5.5
- Source:
- OSV source · Advisory
- CVE-2026-31958GHSA-qjxf-f2mg-c6mc
Tornado is vulnerable to DoS due to too many multipart parts
- Affected:
- <6.5.5
- Fixed in:
- 6.5.5
- Source:
- OSV source · Advisory
