Three Tornado Security Vulnerabilities Patched in Version 6.5.6
ID: 312e2882-49a2-5dd8-9aa1-d03dbd6300c4
STIX ID: report--312e2882-49a2-5dd8-9aa1-d03dbd6300c4
Feed Name: securityonline.info
Tornado 6.5.6 fixes three security flaws: CVE-2026-49853 (CVSS 7.7) where SimpleAsyncHTTPClient can leak Authorization headers across origins when following redirects, CVE-2026-49855 (CVSS 7.5) a gzip-bomb decompression issue that can exhaust memory, and CVE-2026-49854 (CVSS 5.3) a native-extension memory-read bug; the report urges immediate upgrade and lists mitigations (disable follow_redirects or use CurlAsyncHTTPClient, set decompress_response=False, disable the native extension).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
