tornado@4.4.1 vulnerabilities

Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

  • latest version

    6.4.2

  • latest non vulnerable version

  • first published

    14 years ago

  • latest version published

    5 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the tornado package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Regular Expression Denial of Service (ReDoS)

    tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

    Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) due to inefficient cookie parsing that results in quadratic performance. An attacker could cause tornado to consume excessive CPU resources and block the event loop through maliciously crafted cookies.

    How to fix Regular Expression Denial of Service (ReDoS)?

    Upgrade tornado to version 6.4.2 or higher.

    [,6.4.2)
    • M
    HTTP Request Smuggling

    tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

    Affected versions of this package are vulnerable to HTTP Request Smuggling due to the handling of multiple Transfer-Encoding: chunked headers. An attacker can desynchronize the connection and potentially bypass ACLs or poison caches by sending crafted requests with duplicate Transfer-Encoding: chunked headers.

    How to fix HTTP Request Smuggling?

    Upgrade tornado to version 6.4.1 or higher.

    [,6.4.1)
    • M
    Improper Neutralization of CRLF Sequences ('CRLF Injection')

    tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

    Affected versions of this package are vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') through the CurlAsyncHTTPClient headers. An attacker can manipulate HTTP headers and construct unauthorized requests by injecting CRLF sequences into header values.

    How to fix Improper Neutralization of CRLF Sequences ('CRLF Injection')?

    Upgrade tornado to version 6.4.1 or higher.

    [,6.4.1)
    • M
    HTTP Request Smuggling

    tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

    Affected versions of this package are vulnerable to HTTP Request Smuggling via the parse and validate strings capabilities in the int constructor.

    Notes:

    1. This is possible when Tornado is deployed behind certain proxies that interpret those non-standard characters differently.
    2. This is known to apply to older versions of haproxy, although the current release is not affected.

    How to fix HTTP Request Smuggling?

    Upgrade tornado to version 6.3.3 or higher.

    [,6.3.3)
    • M
    HTTP Request Smuggling

    tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

    Affected versions of this package are vulnerable to HTTP Request Smuggling due to improper parsing of the -, +, and _ characters in chunk length and Content-Length fields through the int constructor.

    Note: Exploiting this vulnerability is possible if Tornado is deployed behind certain proxies that interpret non-standard characters differently, such as older versions of haproxy.

    How to fix HTTP Request Smuggling?

    Upgrade tornado to version 6.3.3 or higher.

    [,6.3.3)
    • L
    Open Redirect

    tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

    Affected versions of this package are vulnerable to Open Redirect via the StaticFileHandler class, due to improper validation of the default_filename parameter in the initialize function. Exploiting this vulnerability is possible under specific configurations and might result in a redirect to an attacker-controlled site.

    Note: This vulnerability is still under analysis and we are following up with the maintainers to confirm it.

    How to fix Open Redirect?

    Upgrade tornado to version 6.3.2 or higher.

    [,6.3.2)
    • H
    Denial of Service (DoS)

    tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

    Affected versions of this package are vulnerable to Denial of Service (DoS) attacks due to not enforcing max_size when decompressing compressed zip messages.

    How to fix Denial of Service (DoS)?

    Upgrade tornado to version 5.1 or higher.

    [,5.1)