CVE-2025-47287: 
Python vulnerability analysis and mitigation

Overview

Tornado, a Python web framework and asynchronous networking library, is affected by a vulnerability (CVE-2025-47287) discovered and disclosed on May 15, 2025. The vulnerability exists in the multipart/form-data parser when encountering certain errors, where it logs a warning but continues parsing the remainder of the data. This affects all versions of Tornado prior to 6.5.0, with the vulnerable parser being enabled by default (GitHub Advisory, NVD).

Technical details

The vulnerability stems from the multipart/form-data parser's behavior when encountering errors. Instead of properly handling error conditions, the parser continues processing while generating warning logs. The issue has been assigned a CVSS v3.1 score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). The issue is particularly severe because the logging subsystem operates synchronously, amplifying the impact of the attack (GitHub Advisory, NVD).

Impact

The vulnerability allows remote attackers to generate an extremely high volume of logs, resulting in a Denial of Service (DoS) attack. The synchronous nature of the logging subsystem compounds the DoS impact. The attack can affect system availability without requiring any special privileges or user interaction (GitHub Advisory, Wiz).

Exploitability

The vulnerability can be exploited remotely without requiring any special privileges or user interaction. The attack vector is network-based with low attack complexity, making it relatively straightforward to exploit (GitHub Advisory).

Mitigation and workarounds

The primary mitigation is to upgrade to Tornado version 6.5.0 or later, which contains the patch for this vulnerability. As a temporary workaround, organizations can mitigate the risk by blocking Content-Type: multipart/form-data in a proxy. This prevents the exploitation of the vulnerable parser while waiting for the upgrade (GitHub Advisory, NVD).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

python-tornado: 6.2.0-3+deb12u2

Fixed

sid

python-tornado: 6.4.2-2

Fixed

trixie

python-tornado: 6.4.2-2

Fixed

Ubuntu

Fixed

devel

python-tornado: 6.4.2-2

Fixed

jammy

python-tornado

Affected

jammy (esm-apps)

python-tornado: 6.1.0-3ubuntu0.1~esm2

Fixed

noble

python-tornado: 6.4.0-1ubuntu0.2

Fixed

questing

python-tornado: 6.4.2-2

Fixed

resolute

python-tornado: 6.4.2-2

Fixed

RHEL / CentOS

Fixed

OpenShift

Not Affected

RHEL 8

:highavailability:pcs-0:0.10.18-2.el8_10.5.src

Fixed

RHEL 9

:highavailability:pcs-0:0.11.1-10.el9_0.8.src

Fixed

RHEL 10

python-tornado-0:6.4.2-1.el10_0.1.src

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61732CRITICAL10
  • Python logoPython
  • decepticon-sdk
NoYesSep 24, 2026
GHSA-62mm-xwmv-crhgHIGH8.7
  • Python logoPython
  • khoj
NoYesSep 25, 2026
CVE-2026-57443HIGH7.5
  • Python logoPython
  • scbe-aethermoore
NoYesSep 25, 2026
GHSA-g28h-2cmm-rj9xHIGH7.5
  • Python logoPython
  • langchain-nvidia-ai-endpoints
NoYesSep 24, 2026
CVE-2026-57179MEDIUM4.2
  • Python logoPython
  • social-auth-core
NoYesSep 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management