Логотип exploitDog
bind:"CVE-2025-67724"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-67724"

Количество 11

Количество 11

ubuntu логотип

CVE-2025-67724

4 месяца назад

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2025-67724

4 месяца назад

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-67724

4 месяца назад

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-67724

4 месяца назад

Tornado is a Python web framework and asynchronous networking library. ...

CVSS3: 5.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0838-1

около 1 месяца назад

Security update for python-tornado

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20015-1

3 месяца назад

Security update for python-tornado6

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0010-1

3 месяца назад

Security update for python-tornado6

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20412-1

13 дней назад

Security update for salt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1030-1

12 дней назад

Security update for salt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1029-1

12 дней назад

Security update for salt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1028-1

12 дней назад

Security update for salt

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-67724

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
0%
Низкий
4 месяца назад
redhat логотип
CVE-2025-67724

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
0%
Низкий
4 месяца назад
nvd логотип
CVE-2025-67724

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
0%
Низкий
4 месяца назад
debian логотип
CVE-2025-67724

Tornado is a Python web framework and asynchronous networking library. ...

CVSS3: 5.4
0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0838-1

Security update for python-tornado

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20015-1

Security update for python-tornado6

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0010-1

Security update for python-tornado6

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20412-1

Security update for salt

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:1030-1

Security update for salt

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:1029-1

Security update for salt

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:1028-1

Security update for salt

12 дней назад

Уязвимостей на страницу