<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T05:05:28.886757+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:67146</id>
    <title>ALSA-2026:67146 — Important: python-tornado security update</title>
    <updated>2026-10-06T05:05:29.319430+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: python3-tornado</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
  * tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:67146"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-49853</id>
    <title>BREW-jupyterlab-CVE-2026-49853 — Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient</title>
    <updated>2026-10-06T05:05:29.319505+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: jupyterlab</p>
<p>## Summary</p>
<p>When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.</p>
<p>As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.</p>
<p>Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-49853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339157</id>
    <title>EUVD-2026-339157</title>
    <updated>2026-10-06T05:05:29.319535+00:00</updated>
    <content>EUVD-2026-339157</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49853</id>
    <title>fkie_cve-2026-49853</title>
    <updated>2026-10-06T05:05:29.319550+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-49853"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3x9g-8vmp-wqvf</id>
    <title>GHSA-3x9g-8vmp-wqvf — Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient</title>
    <updated>2026-10-06T05:05:29.319572+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>## Summary</p>
<p>When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.</p>
<p>As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.</p>
<p>Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3x9g-8vmp-wqvf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2727</id>
    <title>OESA-2026-2727 — python-tornado security update</title>
    <updated>2026-10-06T05:05:29.319596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-tornado</p>
<p>Tornado is an open source version of the scalable, non-blocking web server and tools.

Security Fix(es):</p>
<p>When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin. As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default. Beginning in Tornado 6.5.6, SimpleAsyncHTTPClient matches the default behavior of libcurl (and therefore CurlAsyncHTTPClient): When a redirect changes the scheme, host, or port of the url, the Authorization and Cookie headers will be removed when following the redirect.(CVE-2026-49853)</p>
<p>SummaryTornado&amp;apos;s optional native extension `tornado.speedups` implements `websocket_mask` without validating that the `mask` argument is exactly four bytes long. The C function reads four bytes from `mask` unconditionally, even when Python passes a shorter byte string. This can read beyond the provided buffer, exposing up to 3 bytes of uninitialized memory.The behavior is reachable from Tornado&amp;apos;s XSRF token decoder when `xsrf_cookies=True` and the native extension is active. ### MitigationsThis bug is fixed in Tornado 6.5.6. Prior to upgrading to this version, setting the environment variable TORNADO_EXTENSION=0 will disable the vulnerable code (at the expe…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11027-1</id>
    <title>openSUSE-SU-2026:11027-1 — python311-tornado6-6.5.7-1.1 on GA media</title>
    <updated>2026-10-06T05:05:29.319633+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-tornado6-6.5.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11027-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3387</id>
    <title>PYSEC-2026-3387 — Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient</title>
    <updated>2026-10-06T05:05:29.319653+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>## Summary</p>
<p>When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.</p>
<p>As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.</p>
<p>Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:67146</id>
    <title>RLSA-2026:67146 — Important: python-tornado security update</title>
    <updated>2026-10-06T05:05:29.319675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: python-tornado</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)</p>
<p>* tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:67146"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22286-1</id>
    <title>SUSE-SU-2026:22286-1 — Security update for python-tornado6</title>
    <updated>2026-10-06T05:05:29.319699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-tornado6</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22286-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49853</id>
    <title>UBUNTU-CVE-2026-49853</title>
    <updated>2026-10-06T05:05:29.319713+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado</p>
<p>Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49853"/>
  </entry>
</feed>
