Skip to content

[GHSA-7cx3-6m66-7c5m] Tornado vulnerable to excessive logging caused by malformed multipart form data #5558

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed

Conversation

zvxr
Copy link

@zvxr zvxr commented May 19, 2025

Updates

  • Affected products
  • Description

Comments
The version is incorrect-- this was fixed in 6.4.2: GHSA-8w49-h785-mj3c

@github
Copy link
Collaborator

github commented May 19, 2025

Hi there @bdarnell! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to zvxr/advisory-improvement-5558 May 19, 2025 15:09
@bdarnell
Copy link

It looks like you've got two security advisories mixed up. This PR is for GHSA-7cx3-6m66-7c5m, the multipart/form-data parsing issue, which was fixed in 6.5.0. GHSA-8w49-h785-mj3c is the quadratic cookie parsing issue, which was fixed in 6.4.2.

The original advisory is correct and this PR should be closed.

@helixplant
Copy link

Hi @zvxr,
As @bdarnell said, GHSA-8w49-h785-mj3c and GHSA-7cx3-6m66-7c5m are two separate vulnerabilities which is why they have different ranges listed for affected and patched versions. Therefore, I'm closing the community contribution pull request.

@helixplant helixplant closed this May 20, 2025
@github-actions github-actions bot deleted the zvxr-GHSA-7cx3-6m66-7c5m branch May 20, 2025 16:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants