logo

Three Tornado Security Vulnerabilities Patched in Version 6.5.6

ID: 312e2882-49a2-5dd8-9aa1-d03dbd6300c4

STIX ID: report--312e2882-49a2-5dd8-9aa1-d03dbd6300c4

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Do Son

...
...

Tornado 6.5.6 fixes three security flaws: CVE-2026-49853 (CVSS 7.7) where SimpleAsyncHTTPClient can leak Authorization headers across origins when following redirects, CVE-2026-49855 (CVSS 7.5) a gzip-bomb decompression issue that can exhaust memory, and CVE-2026-49854 (CVSS 5.3) a native-extension memory-read bug; the report urges immediate upgrade and lists mitigations (disable follow_redirects or use CurlAsyncHTTPClient, set decompress_response=False, disable the native extension).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.