CVE-2025-67725Patch(tornadoweb / tornado)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tornadoweb tornado systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS). Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if max_header_size has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tornado

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-02-02); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
tornado

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-02: 1Mentions · 2026-04-01: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-02-02: 1Technical Details · 2026-04-01: 102-0204-01
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Critical DoS bugs CVE-2025-67725 (CVSS 8.7) and CVE-2026-31958 in Python-Tornado hit SUSE 12 and Debian 11, vendors ship patches for malicious HTTP and multipart attacks. https://threatcluster.io/cluster/critical-dos-vulnerabilities-in-python-tornado-affecting-sus-0cd1ce2e

    Post summary

    Critical DoS vulnerabilities in Python‑Tornado (CVE‑2025‑67725 and CVE‑2026‑31958) affecting SUSE 12 and Debian 11 have been disclosed, and vendors have released patches to mitigate malicious HTTP and multipart attacks.

    00000216
    128 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Critical security update for #Debian 11 #Bullseye. Patch #Python #Tornado now for CVE-2025-67724 (Header Injection/XSS), CVE-2025-67725/26 (DoS). Read more: 👉 https://tinyurl.com/4f674wpz #Security https://t.co/5oRlxMclaH

    Post summary

    Debian 11 Bullseye has released patches for CVE-2025-67724 (Header Injection/XSS) and CVE-2025-67725/26 (DoS).

    0000087
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptornadowebtornado---

Explore more