OSS Support Hub / Web Framework

Python Web Framework Apache-2.0

Tornado

Python web framework and asynchronous networking library for long polling and WebSockets

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

22.2K+8
GitHub Stars
📦
Latest Release
🔄
Avg. Release Cadence
🐛
216
Open Issues
📅
3 days ago
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

Published: 2026-06-15 Fixed in: 6.5.6

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

Published: 2024-06-06 Fixed in: 6.4.1

Tornado has incomplete validation of cookie attributes

Published: 2026-03-11 Fixed in: 6.5.5

Tornado vulnerable to excessive logging caused by malformed multipart form data

Published: 2025-05-16 Fixed in: 6.5

Tornado XSRF cookie allows side-channel attack against TLS (BREACH attack)

Published: 2022-05-17 Fixed in: 3.2.2

Tornado has an HTTP cookie parsing DoS vulnerability

Published: 2024-11-22 Fixed in: 6.4.2

Tornado has out-of-bounds memory access via C extension

Published: 2026-06-12 Fixed in: 6.5.6

Tornado CRLF injection vulnerability

Published: 2022-05-17 Fixed in: 2.2.1

Tornado has cookie attribute injection via .RequestHandler.set_cookie

Published: 2026-04-03 Fixed in: 6.5.5

Open redirect in Tornado

Published: 2023-05-25 Fixed in: 6.3.2

Alternatives to Tornado

Other Web Framework projects in the Python ecosystem worth evaluating.

Support Options for Tornado

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Tornado — without relying on volunteer maintainers.