CVE-2025-47287

Tornado vulnerable to excessive logging caused by malformed multipart form data

Description

Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.

Category

7.5
CVSS
Severity: High
CVSS 3.1 •
EPSS 0.13%
Affected: tornadoweb tornado
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-47287?
CVE-2025-47287 has been scored as a high severity vulnerability.
How to fix CVE-2025-47287?
To fix CVE-2025-47287, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2025-47287 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-47287 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-47287?
CVE-2025-47287 affects tornadoweb tornado.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.