Known vulnerabilities in python-tornado (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python-tornado (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python-tornado_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU128148 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CVE-2026-35536 |
CWE-74 | Medium | 4.2.1-5.el7_9.3, 6.4.2-1.el9_4.2, 6.4.2-1.el10_0.2, 6.5.5-1.el9_7.1, 6.5.5-1.el10_1.1 | 27.04.2026 |
SB20260427102 SB20260427118 SB20260427149 and 10 more |
||
| #VU128147 - Resource exhaustion CVE-2026-31958 |
CWE-400 | Medium | 4.2.1-5.el7_9.3, 6.4.2-1.el9_4.2, 6.4.2-1.el10_0.2, 6.5.5-1.el9_7.1, 6.5.5-1.el10_1.1 | 27.04.2026 |
SB20260427102 SB20260427109 SB20260427110 and 40 more |
||
| #VU109846 - Allocation of Resources Without Limits or Throttling CVE-2025-47287 |
CWE-770 | Medium | 4.2.1-5.el7_9.1, 6.4.2-1.el9_2.1, 6.4.2-1.el9_4.1, 6.4.2-1.el10_0.1, 6.4.2-2.el9_6.2 | 27.05.2025 |
SB2025052726 SB2025052727 SB2025052728 and 30 more |
||
| #VU101068 - Resource exhaustion CVE-2024-52804 |
CWE-400 | Medium | 6.4.2-1.el9_2, 6.4.2-1.el9_4, 6.4.2-1.el9_5 | 02.12.2024 |
SB2024120203 SB2024120204 SB2024120383 and 16 more |
||
| #VU76397 - URL Redirection to Untrusted Site ('Open Redirect') CVE-2023-28370 |
CWE-601 | Medium | 6.1.0-9.el9 | 22.05.2023 |
SB2023052204 SB2023061333 SB2023062257 and 28 more |