Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. tornado
  4. ›
  5. CVE-2025-67725

CVE-2025-67725: Tornado: Quadratic DoS via Repeated Header Coalescing

July 20, 2026

The HTTPHeaders.add method in Tornado accumulates values using string concatenation when the same header name is repeated. Due to Python string immutability, each concatenation copies the entire string, resulting in O(n²) time complexity.

Given Tornado’s single event loop architecture, a single maliciously crafted HTTP request can block the server’s event loop for an extended period, causing a Denial of Service (DoS).

Severity: High if max_header_size has been increased from its default, low if it has its default value of 64KB.

References

  • github.com/advisories/GHSA-c98p-7wgm-6p64
  • github.com/pypa/advisory-database/tree/main/vulns/tornado/PYSEC-2025-266.yaml
  • github.com/tornadoweb/tornado/commit/771472cfdaeebc0d89a9cc46e249f8891a6b29cd
  • github.com/tornadoweb/tornado/releases/tag/v6.5.3
  • github.com/tornadoweb/tornado/security/advisories/GHSA-c98p-7wgm-6p64
  • nvd.nist.gov/vuln/detail/CVE-2025-67725

Code Behaviors & Features

Detect and mitigate CVE-2025-67725 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 6.5.3

Fixed versions

  • 6.5.3

Solution

Upgrade to version 6.5.3 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption

Source file

pypi/tornado/CVE-2025-67725.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 21 Jul 2026 12:22:08 +0000.