Tornado
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from November 28, 2008 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Tornado before 6.5.7 Credential Leak via Handle Reuse
Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs
Tornado before 6.3.3 HTTP Request Smuggling via Content-Length
Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding
Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop
Perspective 5.0.0 DoS via Loop Expression Evaluation
Tornado vulnerable to excessive logging caused by malformed multipart form data
Monitor Tornado in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.