security advisoryXSSdebian
Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, ...) due to being used unescaped in HTTP headers.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4461-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Daniel Leidert February 01, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : python-tornado Version : 6.1.0-1+deb11u3 CVE ID : CVE-2025-67724 CVE-2025-67725 CVE-2025-67726 Debian Bug : 1122660 1122661 1122663 Tornado is a scalable, non-blocking Python web framework and asynchronous networking library. CVE-2025-67724 Custom reason phrases can cause multiple vulnerabilities (like XSS, header injection, ...) due to being used unescaped in HTTP headers. CVE-2025-67725 A single maliciously crafted HTTP request can cause a possible DoS due to quadratic performance of repeated header lines. CVE-2025-67726 An inefficient algorithm when parsing parameters for HTTP header values can potentially cause a DoS. For Debian 11 bullseye, these problems have been fixed in version 6.1.0-1+deb11u3. We recommend that you upgrade your python-tornado packages. For the detailed security status of python-tornado please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-tornado Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade python-tornado in Debian for several critical fixes against custom reason phrase issues and potential DoS attacks.. Debian Tornado XSS DoS. . Severity: Critical. LinuxSecurity.com Team
Feb 01, 2026
•Critical
Debian LTS