CVE-2025-47287·Python vulnerability
Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attackers to generate an extremely high volume of logs, constituting a DoS attack. This DoS is compounded by the fact that the logging subsystem is synchronous. All versions of Tornado prior to 6.5.0 are affected. The vulnerable parser is enabled by default. Upgrade to Tornado version 6.50 to receive a patch. As a workaround, risk can be mitigated by blocking `Content-Type: multipart/form-data` in a proxy.
- Severity
- high
- Software
- Python
- Fixed in
- 6.5.0
- Published
- 2025-05-15
Affected versions
Until: 6.5.0
Fixed in: 6.5.0
How to fix this CVE
Upgrade Tornado to version 6.5.0 or later to patch a denial-of-service vulnerability in the multipart/form-data parser that allows attackers to flood logs with warning messages through malformed requests. If immediate patching is not possible, block multipart/form-data requests at your reverse proxy or WAF to reduce exposure until the upgrade is deployed.
sudo dnf update python3-tornadoDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST requests with Content-Type: multipart/form-data containing malformed boundary markers or incomplete field headers, followed by log entries containing "Error parsing multipart body" appearing in rapid succession (multiple entries per second)WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Block or rate-limit POST/PUT requests with Content-Type: multipart/form-data header until the application is patched; alternatively, implement request size limits and timeout controls on file upload endpoints to reduce the impact of malformed multipart payloadsHow to check if you are affected
- Run `python3 -c "import tornado; print(tornado.version)"` to check the installed Tornado version; versions below 6.5.0 are vulnerable
- Verify if your application accepts multipart/form-data by checking request handlers: `grep -r "multipart" /path/to/app/ --include="*.py"`
- Search application logs for repeated warnings matching "Error parsing multipart body" or similar parser-related messages that may indicate exploitation attempts
- After patching, re-run the version check to confirm Tornado has been upgraded to 6.5.0 or later
FAQ
What is CVE-2025-47287?
CVE-2025-47287 is a denial-of-service vulnerability in Tornado's multipart/form-data parser that fails to properly handle certain malformed input, causing the framework to generate excessive log warnings through synchronous logging, which can exhaust system resources.
Is CVE-2025-47287 being actively exploited?
No, CVE-2025-47287 is not listed in the CISA Known Exploited Vulnerabilities catalog, and no public exploits are currently available.
What versions of Python are affected by CVE-2025-47287?
All versions of the Tornado library prior to 6.5.0 are affected; the vulnerability is independent of the Python version but exists in the Tornado web framework package.
How do I check if my server is vulnerable to CVE-2025-47287?
Run `python3 -c "import tornado; print(tornado.version)"` and compare the output to version 6.5.0; if your version is lower, your server is vulnerable.
Does Defensia detect CVE-2025-47287?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Tornado is installed on a monitored server, CVE-2025-47287 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-47287. Free for 1 server.
Get started free