Количество 11
Количество 11

CVE-2024-52804
Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.

CVE-2024-52804
Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.

CVE-2024-52804
Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.
CVE-2024-52804
Tornado is a Python web framework and asynchronous networking library. ...

SUSE-SU-2024:4137-1
Security update for python-tornado6

ROS-20250121-06
Уязвимость python3-tornado
GHSA-8w49-h785-mj3c
Tornado has an HTTP cookie parsing DoS vulnerability
ELSA-2025-2872
ELSA-2025-2872: pcs security update (IMPORTANT)
ELSA-2025-2471
ELSA-2025-2471: pcs security update (IMPORTANT)
ELSA-2024-10590
ELSA-2024-10590: python-tornado security update (IMPORTANT)

BDU:2025-00918
Уязвимость асинхронной сетевой библиотеки Tornado, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2024-52804 Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue. | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад |
![]() | CVE-2024-52804 Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue. | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад |
![]() | CVE-2024-52804 Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue. | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад |
CVE-2024-52804 Tornado is a Python web framework and asynchronous networking library. ... | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
![]() | SUSE-SU-2024:4137-1 Security update for python-tornado6 | 0% Низкий | 7 месяцев назад | |
![]() | ROS-20250121-06 Уязвимость python3-tornado | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад |
GHSA-8w49-h785-mj3c Tornado has an HTTP cookie parsing DoS vulnerability | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
ELSA-2025-2872 ELSA-2025-2872: pcs security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2025-2471 ELSA-2025-2471: pcs security update (IMPORTANT) | 3 месяца назад | |||
ELSA-2024-10590 ELSA-2024-10590: python-tornado security update (IMPORTANT) | 7 месяцев назад | |||
![]() | BDU:2025-00918 Уязвимость асинхронной сетевой библиотеки Tornado, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу