<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T11:02:27.457073+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:0930</id>
    <title>ALSA-2026:0930 — Moderate: pcs security update</title>
    <updated>2026-10-03T11:02:28.098516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: pcs, AlmaLinux:8: pcs-snmp</p>
<p>The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities.</p>
<p>Security Fix(es):</p>
<p>* tornado: Tornado Quadratic DoS via Repeated Header Coalescing (CVE-2025-67725)
  * tornado: Tornado Quadratic DoS via Crafted Multipart Parameters (CVE-2025-67726)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:0930"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-67725</id>
    <title>BELL-CVE-2025-67725</title>
    <updated>2026-10-03T11:02:28.098599+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: py3-tornado, Alpaquita:stream: py3-tornado</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-67725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2025-67725</id>
    <title>BREW-jupyterlab-CVE-2025-67725 — Tornado: Quadratic DoS via Repeated Header Coalescing</title>
    <updated>2026-10-03T11:02:28.098622+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: jupyterlab</p>
<p>## Summary</p>
<p>The `HTTPHeaders.add` method in Tornado accumulates values using string concatenation when the same header name is repeated. Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity.</p>
<p>Given Tornado's single event loop architecture, a single maliciously crafted HTTP request can block the server's event loop for an extended period, causing a Denial of Service (DoS).</p>
<p>**Severity:**  **High** if `max_header_size` has been increased from its default, **low** if it has its default value of 64KB.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2025-67725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</id>
    <title>certfr-2026-avi-0901 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T11:02:28.098651+00:00</updated>
    <content>certfr-2026-avi-0901</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-264057</id>
    <title>EUVD-2026-264057</title>
    <updated>2026-10-03T11:02:28.098668+00:00</updated>
    <content>EUVD-2026-264057</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-264057"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-67725</id>
    <title>fkie_cve-2025-67725</title>
    <updated>2026-10-03T11:02:28.098679+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS).  Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if max_header_size has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-67725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-c98p-7wgm-6p64</id>
    <title>GHSA-c98p-7wgm-6p64 — Tornado: Quadratic DoS via Repeated Header Coalescing</title>
    <updated>2026-10-03T11:02:28.098704+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>## Summary</p>
<p>The `HTTPHeaders.add` method in Tornado accumulates values using string concatenation when the same header name is repeated. Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity.</p>
<p>Given Tornado's single event loop architecture, a single maliciously crafted HTTP request can block the server's event loop for an extended period, causing a Denial of Service (DoS).</p>
<p>**Severity:**  **High** if `max_header_size` has been increased from its default, **low** if it has its default value of 64KB.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-c98p-7wgm-6p64"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1130</id>
    <title>OESA-2026-1130 — python-tornado security update</title>
    <updated>2026-10-03T11:02:28.098729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-tornado, openEuler:24.03-LTS-SP2: python-tornado, openEuler:24.03-LTS-SP3: python-tornado, openEuler:20.03-LTS-SP4: python-tornado, openEuler:22.03-LTS-SP3: python-tornado, openEuler:22.03-LTS-SP4: python-tornado, openEuler:24.03-LTS: python-tornado</p>
<p>Tornado is an open source version of the scalable, non-blocking web server and tools.

Security Fix(es):</p>
<p>Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server&amp;apos;s event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS).  Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if max_header_size has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.(CVE-2025-67725)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15838-1</id>
    <title>openSUSE-SU-2025:15838-1 — python311-tornado6-6.5.4-1.1 on GA media</title>
    <updated>2026-10-03T11:02:28.098764+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-tornado6-6.5.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15838-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2025-266</id>
    <title>PYSEC-2025-266</title>
    <updated>2026-10-03T11:02:28.098784+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS).  Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if max_header_size has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2025-266"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:2106</id>
    <title>RHSA-2026:2106 — Red Hat Security Advisory: RHOAI 2.25.2 - Red Hat OpenShift AI</title>
    <updated>2026-10-03T11:02:28.098806+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>llama-stack-k8s-operator: Llama Stack service exposed across namespaces due to missing NetworkPolicy node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects fonttools: fontTools: Arbitrary file write leading to remote code execution via malicious .designspace file urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data github.com/sigstore/fulcio: Fulcio: Denial of Service via crafted OpenID Connect (OIDC) token github.com/argoproj/argo-workflows: argoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic links tornado: Tornado Quadratic DoS via Repeated Header Coalescing tornado: Tornado Quadratic DoS via Crafted Multipart Parameters github.com/expr-lang/expr: Expr: Denial of Service via uncontrolled recursion in expression evaluation github.com/kedacore/keda: KEDA: Arbitrary file read vulnerability in Vault authentication aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:2106"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-1026</id>
    <title>SUSE-EL-9-CLIENT-TOOLS-2026-1026 — Security update 5.0.7 for Multi-Linux Manager Salt Bundle</title>
    <updated>2026-10-03T11:02:28.098850+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.0.7 for Multi-Linux Manager Salt Bundle</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-1026"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-67725</id>
    <title>UBUNTU-CVE-2025-67725</title>
    <updated>2026-10-03T11:02:28.098868+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:25.10: python-tornado</p>
<p>Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method. The function accumulates values using string concatenation when the same header name is repeated, causing a Denial of Service (DoS).  Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity. The severity can vary from high if max_header_size has been increased from its default, to low if it has its default value of 64KB. This issue is fixed in version 6.5.3.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-67725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0195</id>
    <title>WID-SEC-W-2026-0195 — Red Hat Enterprise Linux (pcs / tornado): Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T11:02:28.098897+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in pcs bezüglich der tornado Komponente ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0195"/>
  </entry>
</feed>
