VDB
Sign up
HIGH7.5

PYSEC-2026-1975

Tornado has an HTTP cookie parsing DoS vulnerability

Quick fix

PYSEC-2026-1975 — tornado: upgrade to the fixed version with the command below.

pip install --upgrade 'tornado>=6.4.2'

Details

The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests.

See also CVE-2024-7592 for a similar vulnerability in cpython.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/tornado
Introduced in: 0Fixed in: 6.4.2
Fixpip install --upgrade 'tornado>=6.4.2'

References