← Back to CVEs
CVE-2024-52804
HIGH7.5
Description
Tornado is a Python web framework and asynchronous networking library. The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests. Version 6.4.2 fixes the issue.
CVE Details
CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published11/22/2024
Last Modified11/3/2025
Sourcenvd
Honeypot Sightings0
Affected Products
tornadoweb:tornado
Weaknesses (CWE)
CWE-400CWE-770
References
https://github.com/advisories/GHSA-7pwv-g7hj-39pr(security-advisories@github.com)
https://github.com/tornadoweb/tornado/commit/d5ba4a1695fbf7c6a3e54313262639b198291533(security-advisories@github.com)
https://github.com/tornadoweb/tornado/security/advisories/GHSA-8w49-h785-mj3c(security-advisories@github.com)
https://lists.debian.org/debian-lts-announce/2025/01/msg00000.html(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.