<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:55:29.954934+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:13641</id>
    <title>ALSA-2026:13641 — Moderate: python-tornado security update</title>
    <updated>2026-10-02T12:55:30.789170+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: python3-tornado</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* tornado-python: Tornado: Denial of Service via large multipart bodies (CVE-2026-31958)
  * tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments (CVE-2026-35536)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:13641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07190</id>
    <title>bdu:2026-07190</title>
    <updated>2026-10-02T12:55:30.789257+00:00</updated>
    <content>bdu:2026-07190</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07190"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-31958</id>
    <title>BELL-CVE-2026-31958</title>
    <updated>2026-10-02T12:55:30.789275+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: py3-tornado, Alpaquita:stream: py3-tornado</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-31958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-31958</id>
    <title>BREW-jupyterlab-CVE-2026-31958 — Tornado is vulnerable to DoS due to too many multipart parts</title>
    <updated>2026-10-02T12:55:30.789295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: jupyterlab</p>
<p>In versions of Tornado prior to 6.5.5, the only limit on the number of parts in `multipart/form-data` is the `max_body_size` setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts.</p>
<p>Tornado 6.5.5 introduces new limits on the size and complexity of multipart bodies, including a default limit of 100 parts per request. These limits are configurable if needed; see `tornado.httputil.ParseMultipartConfig`. It is also now possible to disable `multipart/form-data` parsing entirely if it is not required for the application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-31958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0641</id>
    <title>certfr-2026-avi-0641 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T12:55:30.789320+00:00</updated>
    <content>certfr-2026-avi-0641</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-an27706</id>
    <title>Withdrawn: CLEANSTART-2026-AN27706 — Security fixes for CVE-2026-22815, CVE-2026-30922, CVE-2026-31958, CVE-2026-32597, CVE-2026-33175, CVE-2026-34052, CVE-…</title>
    <updated>2026-10-02T12:55:30.789336+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: jupyterhub-k8s-hub</p>
<p>Multiple security vulnerabilities affect the jupyterhub-k8s-hub package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-an27706"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278464</id>
    <title>EUVD-2026-278464</title>
    <updated>2026-10-02T12:55:30.789358+00:00</updated>
    <content>EUVD-2026-278464</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278464"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31958</id>
    <title>fkie_cve-2026-31958</title>
    <updated>2026-10-02T12:55:30.789369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-31958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qjxf-f2mg-c6mc</id>
    <title>GHSA-qjxf-f2mg-c6mc — Tornado is vulnerable to DoS due to too many multipart parts</title>
    <updated>2026-10-02T12:55:30.789392+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>In versions of Tornado prior to 6.5.5, the only limit on the number of parts in `multipart/form-data` is the `max_body_size` setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts.</p>
<p>Tornado 6.5.5 introduces new limits on the size and complexity of multipart bodies, including a default limit of 100 parts per request. These limits are configurable if needed; see `tornado.httputil.ParseMultipartConfig`. It is also now possible to disable `multipart/form-data` parsing entirely if it is not required for the application.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qjxf-f2mg-c6mc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1673</id>
    <title>OESA-2026-1673 — python-tornado security update</title>
    <updated>2026-10-02T12:55:30.789415+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: python-tornado</p>
<p>Tornado is an open source version of the scalable, non-blocking web server and tools.

Security Fix(es):</p>
<p>Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.(CVE-2026-31958)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10374-1</id>
    <title>openSUSE-SU-2026:10374-1 — python311-tornado6-6.5.5-1.1 on GA media</title>
    <updated>2026-10-02T12:55:30.789437+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-tornado6-6.5.5-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10374-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-140</id>
    <title>PYSEC-2026-140</title>
    <updated>2026-10-02T12:55:30.789454+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-140"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:10184</id>
    <title>RHSA-2026:10184 — Red Hat Security Advisory: RHOAI 2.25.5 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T12:55:30.789473+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>vllm: Server Side request forgery (SSRF) in MediaConnector feast: Feast: Remote Code Execution via insecure YAML deserialization openshift-ai: Trusty AI Grants All Authenticated users to list pods in any namespace nltk: Zip Slip Vulnerability in nltk Leading to Code Execution golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3: urllib3 Streaming API improperly handles highly compressed data cbor2: cbor2: Information Disclosure via shared memory in CBORDecoder reuse aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb aiohttp: aiohttp: Denial of Service via specially crafted POST request aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST request python-markdown: denial of service via malformed HTML-like sequences nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function nltk: NLTK: Arbitrary file read via path traversal vulnerability io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files google-cloud-aiplatform: google-cloud-aiplatform: Arbitrary code execution via Stored Cross-Site Scripting (XSS) tensorflow: TensorFlow: Local privilege escalation via…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:10184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-2255</id>
    <title>SUSE-EL-9-CLIENT-TOOLS-2026-2255 — Security update 5.0.8 for Multi-Linux Manager Salt Bundle</title>
    <updated>2026-10-02T12:55:30.789584+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update 5.0.8 for Multi-Linux Manager Salt Bundle</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-el-9-client-tools-2026-2255"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31958</id>
    <title>UBUNTU-CVE-2026-31958</title>
    <updated>2026-10-02T12:55:30.789601+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:25.10: python-tornado, Ubuntu:26.04:LTS: python-tornado</p>
<p>Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-31958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1112</id>
    <title>WID-SEC-W-2026-1112 — Red Hat Enterprise Linux (pcs): Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-02T12:55:30.789630+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (pcs) ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1112"/>
  </entry>
</feed>
