CVE-2025-67726 | tornadoweb tornado up to 6.5.2 Parameters httputil.py string.count iteration (Nessus ID 278566)
A vulnerability described as problematic has been identified in tornadoweb tornado up to 6.5.2. Impacted is the function string.count of the file httputil.py of the component Parameters Handler. Such manipulation leads to excessive iteration.
This vulnerability is referenced as CVE-2025-67726. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.