Package compatibility

Tornado 6.2

What Python versions does this Tornado version support?

Compatibility is derived from PyPI requires_python and Trove classifiers. CompatHub does not independently test every combination.

Declared Python requirement

requires_python
>=3.7,<3.11
Tip version
6.2
Source
PyPI (requires_python / classifiers)

Python compatibility matrix

Evaluated against CompatHub Python VersionLines. Compatibility and lifecycle status are separate signals.

Other Tornado lines

Security

Advisories affecting Tornado 6.2 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
15
Known exploited
0
Highest CVSS
  • CVE-2025-67726GHSA-jhmp-mqwm-3gq8

    Tornado: Quadratic DoS via Crafted Multipart Parameters

    Affected:
    <6.5.3
    Fixed in:
    6.5.3
    Source:
    OSV source · Advisory
  • CVE-2025-67725GHSA-c98p-7wgm-6p64

    Tornado: Quadratic DoS via Repeated Header Coalescing

    Affected:
    <6.5.3
    Fixed in:
    6.5.3
    Source:
    OSV source · Advisory
  • CVE-2025-67724GHSA-pr2v-jx2c-wg9f

    Tornado vulnerable to Header Injection and XSS via reason argument

    Affected:
    <6.5.3
    Fixed in:
    6.5.3
    Source:
    OSV source · Advisory
  • CVE-2026-49853PYSEC-2026-3387

    Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source · Advisory
  • CVE-2026-49855PYSEC-2026-3389

    tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source · Advisory
  • CVE-2026-49854PYSEC-2026-3388

    Tornado has out-of-bounds memory access via C extension

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source · Advisory
  • CVE-2025-47287PYSEC-2026-1974

    Tornado vulnerable to excessive logging caused by malformed multipart form data

    Affected:
    <6.5
    Fixed in:
    6.5
    Source:
    OSV source · Advisory
  • CVE-2024-52804PYSEC-2026-1975

    Tornado has an HTTP cookie parsing DoS vulnerability

    Affected:
    <6.4.2
    Fixed in:
    6.4.2
    Source:
    OSV source · Advisory
  • GHSA-pw6j-qg29-8w7f

    Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

    Affected:
    <6.5.7
    Fixed in:
    6.5.7
    Source:
    OSV source
  • CVE-2026-49853GHSA-3x9g-8vmp-wqvf

    Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source
  • CVE-2026-49855GHSA-mgf9-4vpg-hj56

    tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source
  • CVE-2026-49854GHSA-cx3h-4qpv-8hc9

    Tornado has out-of-bounds memory access via C extension

    Affected:
    <6.5.6
    Fixed in:
    6.5.6
    Source:
    OSV source
  • CVE-2026-35536GHSA-fqwm-6jpj-5wxc

    Tornado has cookie attribute injection via .RequestHandler.set_cookie

    Affected:
    <6.5.5
    Fixed in:
    6.5.5
    Source:
    OSV source · Advisory
  • CVE-2026-35536PYSEC-2026-2287
    Affected:
    <6.5.5
    Fixed in:
    6.5.5
    Source:
    OSV source · Advisory
  • CVE-2026-31958GHSA-qjxf-f2mg-c6mc

    Tornado is vulnerable to DoS due to too many multipart parts

    Affected:
    <6.5.5
    Fixed in:
    6.5.5
    Source:
    OSV source · Advisory