NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #289 most downloaded on PyPI
Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.
Last release 7 days ago
22 Sep 2026
Ships fairly regularly
a new release about every 3 months
Most releases are documented
notes for 40 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
16 years old
87 releases · first in 2010
Nothing published for this version
Nothing published for this version
Fixed a bug that could sometimes cause a timeout to fire after being cancelled.
Fixed a bug that could sometimes cause a timeout to fire after being cancelled.
.AsyncTestCase once again passes along arguments to test methods, making it compatible with extensions such as Nose's test generators.
.StaticFileHandler can again compress its responses when gzip is enabled.
simple_httpclient passes its max_buffer_size argument to the underlying stream.
Fixed a reference cycle that can lead to increased memory consumption.
.add_accept_handler will now limit the number of times it will call ~socket.socket.accept per .IOLoop iteration, addressing a potential starvation issue.
Improved error handling in .IOStream.connect (primarily for FreeBSD systems)
One column per quarter.
The build will now fall back to pure-python mode if the C extension fails to build for any reason (previously it would fall back for some errors but n
The build will now fall back to pure-python mode if the C extension fails to build for any reason (previously it would fall back for some errors but not others).
.IOLoop.call_at and .IOLoop.call_later now always return a timeout handle for use with .IOLoop.remove_timeout.
If any callback of a .PeriodicCallback or .IOStream returns a .Future, any error raised in that future will now be logged (similar to the behavior of .IOLoop.add_callback).
Fixed an exception in client-side websocket connections when the connection is closed.
simple_httpclient once again correctly handles 204 status codes with no content-length header.
Fixed a regression in simple_httpclient that would result in timeouts for certain kinds of errors.
Nothing published for this version
This makes it safe to include in compressed pages without being vulnerable to the BREACH attack _. This applies to most applications that use both the…
The XSRF token is now encoded with a random mask on each request. This makes it safe to include in compressed pages without being vulnerable to the BREACH attack. This applies to most applications that use both the xsrf_cookies and gzip options (or have gzip applied by a proxy).
If Tornado 3.2.2 is run at the same time as older versions on the same domain, there is some potential for issues with the differing cookie versions. The .Application setting xsrf_cookie_version=1 can be used for a transitional period to generate the older cookie format on newer servers.
tornado.platform.asyncio is now compatible with trollius version 0.3.
The new cookie format fixes a vulnerability that may be present in applications that use multiple cookies where the name of one cookie is a prefix of…
The signed-value format used by .RequestHandler.set_secure_cookie and .RequestHandler.get_secure_cookie has changed to be more secure. This is a disruptive change. The secure_cookie functions take new version parameters to support transitions between cookie formats.
The new cookie format fixes a vulnerability that may be present in applications that use multiple cookies where the name of one cookie is a prefix of the name of another.
To minimize disruption, cookies in the older format will be accepted by default until they expire. Applications that may be vulnerable can reject all cookies in the older format by passing min_version=2 to .RequestHandler.get_secure_cookie.
Thanks to Joost Pol of Certified Secure for reporting this issue.
Signed cookies issued by .RequestHandler.set_secure_cookie in Tornado 3.2.1 cannot be read by older releases. If you need to run 3.2.1 in parallel with older releases, you can pass version=1 to .RequestHandler.set_secure_cookie to issue cookies that are backwards-compatible (but have a known weakness, so this option should only be used for a transitional period).
The C extension used to speed up the websocket module now compiles correctly on Windows with MSVC and 64-bit mode. The fallback to the pure-Python alternative now works correctly on Mac OS X machines with no C compiler installed.
Nothing published for this version
.StaticFileHandler no longer fails if the client requests a Range that is larger than the entire file (Facebook has a crawler that does this).
.StaticFileHandler no longer fails if the client requests a Range that is larger than the entire file (Facebook has a crawler that does this).
.RequestHandler.on_connection_close now works correctly on subsequent requests of a keep-alive connection.
Nothing published for this version
tornado.auth.TwitterMixin now defaults to version 1.1 of the Twitter API, instead of version 1.0 which is being discontinued on June 11 _. It also now
tornado.auth.TwitterMixin now defaults to version 1.1 of the Twitter API, instead of version 1.0 which is being discontinued on June 11. It also now uses HTTPS when talking to Twitter.
Fixed a potential memory leak with a long chain of .gen.coroutine or gen.engine functions.
The interface of tornado.auth.FacebookGraphMixin is now consistent with its documentation and the rest of the module. The get_authenticated_user and f
The interface of tornado.auth.FacebookGraphMixin is now consistent with its documentation and the rest of the module. The get_authenticated_user and facebook_request methods return a Future and the callback argument is optional.
The tornado.testing.gen_test decorator will no longer be recognized as a (broken) test by nose.
Work around a bug in Ubuntu 13.04 betas involving an incomplete backport of the ssl.match_hostname function.
tornado.websocket.websocket_connect now fails cleanly when it attempts to connect to a non-websocket url.
tornado.testing.LogTrapTestCase once again works with byte strings on Python 2.
The request attribute of tornado.httpclient.HTTPResponse is now always an ~tornado.httpclient.HTTPRequest, never a _RequestProxy.
Exceptions raised by the tornado.gen module now have better messages when tuples are used as callback keys.
Nothing published for this version
Fixed a memory leak in tornado.stack_context that was especially likely with long-running @gen.engine functions.
Fixed a memory leak in tornado.stack_context that was especially likely with long-running @gen.engine functions.
tornado.auth.TwitterMixin now works on Python 3.
Fixed a bug in which IOStream.read_until_close with a streaming callback would sometimes pass the last chunk of data to the final callback instead of the streaming callback.
Nothing published for this version
Nothing published for this version
tornado.web.RequestHandler.set_header now properly sanitizes input values to protect against header injection, response splitting, etc. (it has always
tornado.web.RequestHandler.set_header now properly sanitizes input values to protect against header injection, response splitting, etc. (it has always attempted to do this, but the check was incorrect). Note that redirects, the most likely source of such bugs, are protected by a separate check in .RequestHandler.redirect.
Colored logging configuration in tornado.options is compatible with Python 3.2.3 (and 3.3).
Nothing published for this version
Fixed handling of closed connections with the epoll (i.e. Linux) IOLoop. Previously, closed connections could be shut down too early, which most often
Fixed handling of closed connections with the epoll (i.e. Linux) IOLoop. Previously, closed connections could be shut down too early, which most often manifested as "Stream is closed" exceptions in SimpleAsyncHTTPClient.
Fixed a case in which chunked responses could be closed prematurely, leading to truncated output.
IOStream.connect now reports errors more consistently via logging and the close callback (this affects e.g. connections to localhost on FreeBSD).
IOStream.read_bytes again accepts both int and long arguments.
PeriodicCallback no longer runs repeatedly when IOLoop iterations complete faster than the resolution of time.time() (mainly a problem on Windows).
Listening for IOLoop.ERROR alone is no longer sufficient for detecting closed connections on an otherwise unused socket. IOLoop.ERROR must always be used in combination with READ or WRITE.
Nothing published for this version
Nothing published for this version
We are pleased to announce the release of Tornado 1.2.1, available from https://github.com/downloads/facebook/tornado/tornado-1.2.1.tar.gz
We are pleased to announce the release of Tornado 1.2.1, available from https://github.com/downloads/facebook/tornado/tornado-1.2.1.tar.gz This release contains only two small changes relative to version 1.2: * FacebookGraphMixin has been updated to work with a recent change to the Facebook API. * Running "setup.py install" will no longer attempt to automatically install pycurl. This wasn't working well on platforms where the best way to install pycurl is via something like apt-get instead of easy_install. This is an important upgrade if you are using FacebookGraphMixin, but otherwise it can be safely ignored.
Nothing published for this version
Tornado 1.1.1 is a BACKWARDS-INCOMPATIBLE security update that fixes an XSRF vulnerability. It is available at https://github.com/downloads/facebook/t…
Tornado 1.1.1 is a BACKWARDS-INCOMPATIBLE security update that fixes an XSRF vulnerability. It is available at https://github.com/downloads/facebook/tornado/tornado-1.1.1.tar.gz This is a backwards-incompatible change. Applications that previously relied on a blanket exception for XMLHTTPRequest may need to be modified to explicitly include the XSRF token when making ajax requests. The tornado chat demo application demonstrates one way of adding this token (specifically the function postJSON in demos/chat/static/chat.js). More information about this change and its justification can be found at http://www.djangoproject.com/weblog/2011/feb/08/security/ http://weblog.rubyonrails.org/2011/2/8/csrf-protection-bypass-in-ruby-on-rails
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →