{"id":"USN-7950-1","summary":"python-tornado vulnerabilities","details":"It was discovered that Tornado incorrectly handled special characters in\nHTTP headers. An attacker could possibly use this issue to execute a cross-\nsite scripting (XSS) attack. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.04, and Ubuntu 25.10.\n(CVE-2025-67724)\n\nIt was discovered that Tornado incorrectly handled repeated HTTP headers.\nAn attacker could possibly use this issue to cause Tornado to use excessive\nresources, causing a denial of service. (CVE-2025-67725)\n\nIt was discovered that Tornado incorrectly handled parsing of certain HTTP\nheader values. An attacker could possibly use this issue to cause Tornado\nto use excessive resources, causing a denial of service. (CVE-2025-67726)","modified":"2026-02-10T04:50:47Z","published":"2026-01-08T18:39:42Z","related":["UBUNTU-CVE-2025-67724","UBUNTU-CVE-2025-67725","UBUNTU-CVE-2025-67726"],"upstream":["CVE-2025-67724","CVE-2025-67725","CVE-2025-67726","UBUNTU-CVE-2025-67724","UBUNTU-CVE-2025-67725","UBUNTU-CVE-2025-67726"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7950-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-67724"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-67725"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-67726"}],"affected":[{"package":{"name":"python-tornado","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/python-tornado@4.2.1-1ubuntu3.1+esm2?arch=source&distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.1-1ubuntu3.1+esm2"}]}],"versions":["4.2.1-1ubuntu2","4.2.1-1ubuntu3","4.2.1-1ubuntu3.1","4.2.1-1ubuntu3.1+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.2.1-1ubuntu3.1+esm2","binary_name":"python-tornado"},{"binary_version":"4.2.1-1ubuntu3.1+esm2","binary_name":"python3-tornado"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7950-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67725"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67726"}]}}},{"package":{"name":"python-tornado","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/python-tornado@4.5.3-1ubuntu0.2+esm2?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.5.3-1ubuntu0.2+esm2"}]}],"versions":["4.5.1-2.1~build2","4.5.2-1","4.5.3-1","4.5.3-1ubuntu0.1","4.5.3-1ubuntu0.2","4.5.3-1ubuntu0.2+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.5.3-1ubuntu0.2+esm2","binary_name":"python-tornado"},{"binary_version":"4.5.3-1ubuntu0.2+esm2","binary_name":"python3-tornado"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7950-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:18.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67725"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67726"}]}}},{"package":{"name":"python-tornado","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/python-tornado@6.0.3+really5.1.1-3ubuntu0.1~esm3?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3+really5.1.1-3ubuntu0.1~esm3"}]}],"versions":["5.1.1-4ubuntu1","5.1.1-4ubuntu5","6.0.3+really5.1.1-2","6.0.3+really5.1.1-2build1","6.0.3+really5.1.1-2build2","6.0.3+really5.1.1-3","6.0.3+really5.1.1-3ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"6.0.3+really5.1.1-3ubuntu0.1~esm3","binary_name":"python3-tornado"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7950-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:20.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67724"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67725"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67726"}]}}},{"package":{"name":"python-tornado","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/python-tornado@6.1.0-3ubuntu0.1~esm4?arch=source&distro=esm-apps/jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.0-3ubuntu0.1~esm4"}]}],"versions":["6.1.0-1build1","6.1.0-2","6.1.0-3","6.1.0-3build1","6.1.0-3ubuntu0.1~esm1","6.1.0-3ubuntu0.1~esm2"],"ecosystem_specific":{"binaries":[{"binary_version":"6.1.0-3ubuntu0.1~esm4","binary_name":"python3-tornado"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7950-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:22.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67724"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67725"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67726"}]}}},{"package":{"name":"python-tornado","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/python-tornado@6.4.0-1ubuntu0.4?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.0-1ubuntu0.4"}]}],"versions":["6.3.2-1","6.4.0-0ubuntu1","6.4.0-1","6.4.0-1build1","6.4.0-1ubuntu0.1","6.4.0-1ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_version":"6.4.0-1ubuntu0.4","binary_name":"python3-tornado"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7950-1.json","cves_map":{"ecosystem":"Ubuntu:24.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67724"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67725"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67726"}]}}},{"package":{"name":"python-tornado","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/python-tornado@6.4.2-3ubuntu0.2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.2-3ubuntu0.2"}]}],"versions":["6.4.2-1","6.4.2-2","6.4.2-2ubuntu1","6.4.2-3"],"ecosystem_specific":{"binaries":[{"binary_version":"6.4.2-3ubuntu0.2","binary_name":"python3-tornado"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7950-1.json","cves_map":{"ecosystem":"Ubuntu:25.10","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67724"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67725"},{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2025-67726"}]}}}],"schema_version":"1.7.3"}