CVE-2025-47287
published 2025-05-15CVE-2025-47287: Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.67%
48.5th percentile
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | python-tornado | < python-tornado 6.2.0-3+deb12u2 (bookworm) | python-tornado 6.2.0-3+deb12u2 (bookworm) |
| tornadoweb | tornado | < 6.5.0 | 6.5.0 |
| tornadoweb | tornado | >= 0 < 6.5 | 6.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python-tornado vulnerability
osv·2025-06-02·CVSS 7.5
CVE-2025-47287 [HIGH] python-tornado vulnerability
python-tornado vulnerability
It was discovered that Tornado inefficiently handled requests when
parsing certain form data. An attacker could possibly use this issue to
increase resource utilization leading to a denial of service. This issue
was only addressed in Ubuntu 24.04 LTS and Ubuntu 22.04 LTS.
(CVE-2025-47287)
GHSA
Tornado vulnerable to excessive logging caused by malformed multipart form data
ghsa·2025-05-16
CVE-2025-47287 [HIGH] CWE-770 Tornado vulnerable to excessive logging caused by malformed multipart form data
Tornado vulnerable to excessive logging caused by malformed multipart form data
### Summary
When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.
### Affected versions
All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.
### Solution
Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
OSV
Tornado vulnerable to excessive logging caused by malformed multipart form data
osv·2025-05-16
CVE-2025-47287 [HIGH] Tornado vulnerable to excessive logging caused by malformed multipart form data
Tornado vulnerable to excessive logging caused by malformed multipart form data
### Summary
When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous.
### Affected versions
All versions of Tornado prior to 6.5 are affected. The vulnerable parser is enabled by default.
### Solution
Upgrade to Tornado version 6.5. In the meantime, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
OSV
CVE-2025-47287: Tornado is a Python web framework and asynchronous networking library
osv·2025-05-15·CVSS 7.5
CVE-2025-47287 [HIGH] CVE-2025-47287: Tornado is a Python web framework and asynchronous networking library
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
Ubuntu
Tornado vulnerability
vendor_ubuntu·2025-06-02·CVSS 7.5
CVE-2025-47287 [HIGH] Tornado vulnerability
Title: Tornado vulnerability
Summary: Tornado could be made to consume excessive resources when processing
specially crafted HTTP requests.
It was discovered that Tornado inefficiently handled requests when
parsing certain form data. An attacker could possibly use this issue to
increase resource utilization leading to a denial of service. This issue
was only addressed in Ubuntu 24.04 LTS and Ubuntu 22.04 LTS.
(CVE-2025-47287)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tornado: Tornado Multipart Form-Data Denial of Service
vendor_redhat·2025-05-15·CVSS 7.5
CVE-2025-47287 [HIGH] CWE-770 tornado: Tornado Multipart Form-Data Denial of Service
tornado: Tornado Multipart Form-Data Denial of Service
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
A flaw was found in Tornado. This vulnerability can lead to a a denial of service by generating
Debian
CVE-2025-47287: python-tornado - Tornado is a Python web framework and asynchronous networking library. When Torn...
vendor_debian·2025·CVSS 7.5
CVE-2025-47287 [HIGH] CVE-2025-47287: python-tornado - Tornado is a Python web framework and asynchronous networking library. When Torn...
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
Scope: local
bookworm: resolved (fixed in 6.2.0-3+deb12u2)
bullseye: resolved (fixed in 6.1.0-1+deb11u2)
forky: resolved (fixed in 6.4.2-2)
sid: resolve
No detection rules found.
No public exploits indexed.
2025-05-15
Published