Loading
Generated remediation guidance and an executive summary. No account required.
Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.
Cite this page
CVE-2014-9720. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2014-9720
Use CWE-203, Tornadoweb vendor hub and Tornado product page to widen CVE-2014-9720 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-31958, CVE-2025-67726 and CVE-2025-67725 for nearby disclosures in the same product family.