Intel

AIKIDO-2026-840929

tornado is vulnerable to Denial of Service

Denial of ServiceCVE-2025-67726 Published Jul 17, 2026

75

High Risk

This Affects:

PYTHONtornado
0.0.0 - 6.5.2
Fixed in 6.5.3
Are you affected? Scan for Free

TL;DR

The _parseparam function in Tornado's httputil.py is used to parse specific HTTP header values, such as those in multipart/form-data. This function uses an inefficient algorithm that repeatedly calls string.count() within a nested loop while processing quoted semicolons (e.g., param=";"). As a result, if an attacker sends a request with a large number of maliciously crafted parameters in a Content-Disposition header, the server's CPU usage increases quadratically (O(n^2)) during parsing. Due to Tornado's single event loop architecture, a single malicious request can cause the entire server to become unresponsive for an extended period, leading to a Denial of Service (DoS).

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

tornado is vulnerable to Denial of Service in versions 0.0.0 - 6.5.2.

How to fix this

Upgrade the tornado library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform