Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

ubuntu логотип

CVE-2025-67724

8 месяцев назад

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2025-67724

8 месяцев назад

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-67724

8 месяцев назад

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-67724

8 месяцев назад

Tornado is a Python web framework and asynchronous networking library. ...

CVSS3: 5.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0838-1

6 месяцев назад

Security update for python-tornado

EPSS: Низкий
github логотип

GHSA-pr2v-jx2c-wg9f

около 1 месяца назад

Tornado vulnerable to Header Injection and XSS via reason argument

CVSS3: 5.4
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20015-1

7 месяцев назад

Security update for python-tornado6

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0010-1

8 месяцев назад

Security update for python-tornado6

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20412-1

5 месяцев назад

Security update for salt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1030-1

5 месяцев назад

Security update for salt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1029-1

5 месяцев назад

Security update for salt

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1028-1

5 месяцев назад

Security update for salt

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-67724

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2025-67724

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-67724

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-67724

Tornado is a Python web framework and asynchronous networking library. ...

CVSS3: 5.4
0%
Низкий
8 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0838-1

Security update for python-tornado

0%
Низкий
6 месяцев назад
github логотип
GHSA-pr2v-jx2c-wg9f

Tornado vulnerable to Header Injection and XSS via reason argument

CVSS3: 5.4
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20015-1

Security update for python-tornado6

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0010-1

Security update for python-tornado6

8 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20412-1

Security update for salt

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1030-1

Security update for salt

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1029-1

Security update for salt

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1028-1

Security update for salt

5 месяцев назад

Уязвимостей на страницу