<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:10:44 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:8135 — Important: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:8135</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: python3-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado Multipart Form-Data Denial of Service (CVE-2025-47287)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: python3-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado Multipart Form-Data Denial of Service (CVE-2025-47287)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:8135</guid>
    </item>
    <item>
      <title>bdu:2025-08361</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08361</link>
      <description>bdu:2025-08361</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08361</guid>
    </item>
    <item>
      <title>BREW-jupyterlab-CVE-2025-47287 — Tornado vulnerable to excessive logging caused by malformed multipart form data</title>
      <link>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2025-47287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.&lt;/p&gt;
&lt;p&gt;### Solution&lt;/p&gt;
&lt;p&gt;Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.&lt;/p&gt;
&lt;p&gt;### Solution&lt;/p&gt;
&lt;p&gt;Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2025-47287</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0760 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0760</link>
      <description>certfr-2025-avi-0760</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0760</guid>
    </item>
    <item>
      <title>EUVD-2026-241685</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-241685</link>
      <description>EUVD-2026-241685</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-241685</guid>
    </item>
    <item>
      <title>fkie_cve-2025-47287</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-47287</link>
      <description>&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-47287</guid>
    </item>
    <item>
      <title>GHSA-7cx3-6m66-7c5m — Tornado vulnerable to excessive logging caused by malformed multipart form data</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7cx3-6m66-7c5m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.&lt;/p&gt;
&lt;p&gt;### Solution&lt;/p&gt;
&lt;p&gt;Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.&lt;/p&gt;
&lt;p&gt;### Solution&lt;/p&gt;
&lt;p&gt;Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7cx3-6m66-7c5m</guid>
    </item>
    <item>
      <title>OESA-2025-1554 — python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1554</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is an open source version of the scalable, non-blocking web server and tools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. When Tornado&amp;amp;apos;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.(CVE-2025-47287)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is an open source version of the scalable, non-blocking web server and tools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. When Tornado&amp;amp;apos;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.(CVE-2025-47287)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1554</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15153-1 — python311-tornado6-6.5-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15153-1</link>
      <description>&lt;p&gt;python311-tornado6-6.5-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-tornado6-6.5-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15153-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-1974 — Tornado vulnerable to excessive logging caused by malformed multipart form data</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-1974</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.&lt;/p&gt;
&lt;p&gt;### Solution&lt;/p&gt;
&lt;p&gt;Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.&lt;/p&gt;
&lt;p&gt;### Affected versions&lt;/p&gt;
&lt;p&gt;All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.&lt;/p&gt;
&lt;p&gt;### Solution&lt;/p&gt;
&lt;p&gt;Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-1974</guid>
    </item>
    <item>
      <title>RHSA-2025:8223 — Red Hat Security Advisory: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:8223</link>
      <description>&lt;p&gt;tornado: Tornado Multipart Form-Data Denial of Service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tornado: Tornado Multipart Form-Data Denial of Service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:8223</guid>
    </item>
    <item>
      <title>SUSE-EL-9-CLIENT-TOOLS-2025-2499 — Security update 5.0.5 for Multi-Linux Manager Salt Bundle</title>
      <link>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2025-2499</link>
      <description>&lt;p&gt;Security update 5.0.5 for Multi-Linux Manager Salt Bundle&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update 5.0.5 for Multi-Linux Manager Salt Bundle&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2025-2499</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-47287</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-47287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:25.10: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:25.10: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. When Tornado&amp;#39;s ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-47287</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1143 — Red Hat Enterprise Linux (python-tornado): Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1143</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1143</guid>
    </item>
  </channel>
</rss>
