<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T19:23:18.214854+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:8135</id>
    <title>ALSA-2025:8135 — Important: python-tornado security update</title>
    <updated>2026-10-03T19:23:19.074995+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: python3-tornado</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* tornado: Tornado Multipart Form-Data Denial of Service (CVE-2025-47287)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:8135"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08361</id>
    <title>bdu:2025-08361</title>
    <updated>2026-10-03T19:23:19.075116+00:00</updated>
    <content>bdu:2025-08361</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08361"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2025-47287</id>
    <title>BREW-jupyterlab-CVE-2025-47287 — Tornado vulnerable to excessive logging caused by malformed multipart form data</title>
    <updated>2026-10-03T19:23:19.075149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: jupyterlab</p>
<p>### Summary</p>
<p>When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.</p>
<p>### Affected versions</p>
<p>All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.</p>
<p>### Solution</p>
<p>Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2025-47287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0760</id>
    <title>certfr-2025-avi-0760 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T19:23:19.075203+00:00</updated>
    <content>certfr-2025-avi-0760</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0760"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-241685</id>
    <title>EUVD-2026-241685</title>
    <updated>2026-10-03T19:23:19.075251+00:00</updated>
    <content>EUVD-2026-241685</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-241685"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-47287</id>
    <title>fkie_cve-2025-47287</title>
    <updated>2026-10-03T19:23:19.075272+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-47287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7cx3-6m66-7c5m</id>
    <title>GHSA-7cx3-6m66-7c5m — Tornado vulnerable to excessive logging caused by malformed multipart form data</title>
    <updated>2026-10-03T19:23:19.075313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>### Summary</p>
<p>When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.</p>
<p>### Affected versions</p>
<p>All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.</p>
<p>### Solution</p>
<p>Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7cx3-6m66-7c5m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1554</id>
    <title>OESA-2025-1554 — python-tornado security update</title>
    <updated>2026-10-03T19:23:19.075366+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: python-tornado</p>
<p>Tornado is an open source version of the scalable, non-blocking web server and tools.

Security Fix(es):</p>
<p>Tornado is a Python web framework and asynchronous networking library. When Tornado&amp;apos;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.(CVE-2025-47287)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1554"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15153-1</id>
    <title>openSUSE-SU-2025:15153-1 — python311-tornado6-6.5-1.1 on GA media</title>
    <updated>2026-10-03T19:23:19.075429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-tornado6-6.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15153-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1974</id>
    <title>PYSEC-2026-1974 — Tornado vulnerable to excessive logging caused by malformed multipart form data</title>
    <updated>2026-10-03T19:23:19.075467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>### Summary</p>
<p>When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.</p>
<p>### Affected versions</p>
<p>All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.</p>
<p>### Solution</p>
<p>Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1974"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:8223</id>
    <title>RHSA-2025:8223 — Red Hat Security Advisory: python-tornado security update</title>
    <updated>2026-10-03T19:23:19.075516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tornado: Tornado Multipart Form-Data Denial of Service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:8223"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2025-2499</id>
    <title>SUSE-EL-9-CLIENT-TOOLS-2025-2499 — Security update 5.0.5 for Multi-Linux Manager Salt Bundle</title>
    <updated>2026-10-03T19:23:19.075547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.0.5 for Multi-Linux Manager Salt Bundle</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2025-2499"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-47287</id>
    <title>UBUNTU-CVE-2025-47287</title>
    <updated>2026-10-03T19:23:19.075582+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:25.10: python-tornado</p>
<p>Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-47287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1143</id>
    <title>WID-SEC-W-2025-1143 — Red Hat Enterprise Linux (python-tornado): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T19:23:19.075636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1143"/>
  </entry>
</feed>
