UbuntuUpdates.org

Bugs fixes in "python-tornado"

Origin Bug number Title Date fixed
CVE CVE-2025-67724 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in H 2026-01-09
CVE CVE-2025-67726 Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters 2026-01-08
CVE CVE-2025-67725 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can blo 2026-01-08
CVE CVE-2025-67724 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in H 2026-01-08
CVE CVE-2025-67726 Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters 2026-01-08
CVE CVE-2025-67725 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can blo 2026-01-08
CVE CVE-2025-67724 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in H 2026-01-08
CVE CVE-2025-67726 Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters 2026-01-08
CVE CVE-2025-67725 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can blo 2026-01-08
CVE CVE-2025-67724 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in H 2026-01-08
CVE CVE-2025-47287 Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo 2025-06-02
CVE CVE-2025-47287 Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo 2025-06-02
CVE CVE-2025-47287 Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo 2025-06-02
CVE CVE-2025-47287 Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it lo 2025-06-02
CVE CVE-2024-52804 Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 2024-12-11
CVE CVE-2024-52804 Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 2024-12-11
Launchpad 1903733 Out of memory issue for websocket client 2021-01-28
Launchpad 1903733 Out of memory issue for websocket client 2021-01-19
Debian 938220 python-tornado: Python2 removal in sid/bullseye 2020-04-23
Debian 938220 python-tornado: Python2 removal in sid/bullseye 2020-04-22



About   -   Send Feedback to @ubuntu_updates