OSS Support Hub / Web Framework

Python Web Framework Apache-2.0

Tornado

Python web framework and asynchronous networking library for long polling and WebSockets

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

22.2K
GitHub Stars
📦
Latest Release
🔄
Avg. Release Cadence
🐛
220
Open Issues
📅
3 days ago
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-05-15

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado

Published: 2024-06-06 Fixed in: 6.4.1

Tornado has incomplete validation of cookie attributes

Published: 2026-03-11 Fixed in: 6.5.5

Tornado vulnerable to excessive logging caused by malformed multipart form data

Published: 2025-05-16 Fixed in: 6.5

Tornado XSRF cookie allows side-channel attack against TLS (BREACH attack)

Published: 2022-05-17 Fixed in: 3.2.2

Tornado has an HTTP cookie parsing DoS vulnerability

Published: 2024-11-22 Fixed in: 6.4.2

Tornado CRLF injection vulnerability

Published: 2022-05-17 Fixed in: 2.2.1

Tornado has cookie attribute injection via .RequestHandler.set_cookie

Published: 2026-04-03 Fixed in: 6.5.5

Open redirect in Tornado

Published: 2023-05-25 Fixed in: 6.3.2

Tornado is vulnerable to DoS due to too many multipart parts

Published: 2026-03-12 Fixed in: 6.5.5

Tornado vulnerable to HTTP request smuggling via improper parsing of `Content-Length` fields and chunk lengths

Published: 2023-08-14 Fixed in: 6.3.3

Alternatives to Tornado

Other Web Framework projects in the Python ecosystem worth evaluating.

Support Options for Tornado

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Tornado — without relying on volunteer maintainers.

Talk to an Expert →