Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom "reason" phrases (the "Not Found" in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py3-tornado | Jun 18, 2026 | Dec 12, 2025 |
| Amazon Linux Ami 2 | — | Upgrade python-tornado-docUpgrade python3-tornado-docUpgrade python3-tornadoUpgrade python-tornado-debuginfoUpgrade python3-tornado-debuginfoUpgrade python-tornado | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade python3-tornado-debuginfoUpgrade python3.13-tornado-debuginfoUpgrade python-tornado-debugsourceUpgrade python3.13-tornado-docUpgrade python3.13-tornado-debugsourceUpgrade python3.13-tornadoUpgrade python-tornado-docUpgrade python3-tornado | Jan 12, 2026 | Dec 12, 2025 |
| Debian | — | Upgrade python-tornado | Feb 2, 2026 | Feb 2, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 12, 2025 |
| Ubuntu | — | Upgrade python3-tornado (Ubuntu Pro)Upgrade python3-tornadoUpgrade python-tornado (Ubuntu Pro) | Jan 9, 2026 | Dec 12, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 6, 2026 | Dec 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub