<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:55:49 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67146 — Important: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67146</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
  * tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
  * tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67146</guid>
    </item>
    <item>
      <title>BREW-jupyterlab-CVE-2026-49855 — tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)</title>
      <link>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-49855</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;Tornado&amp;#39;s gzip decompression routines work in limited-size chunks, but have no overall limit for the total size of decompressed chunks that they will accumulate (There has always been a limit for the total *compressed* size). This allows a malicious server to consume effectively unlimited amounts of memory if it is accessed via SimpleAsyncHTTPClient in its default configuration. `HTTPServer` is not affected in its default configuration, but it is if `decompress_request=True` is set.&lt;/p&gt;
&lt;p&gt;This bug is fixed in Tornado 6.5.6. `max_body_size` is now checked both for the compressed and cumulative decompressed size of the response.&lt;/p&gt;
&lt;p&gt;Prior to upgrading, this issue can be mitigated by setting `decompress_response=False` or using `CurlAsyncHTTPClient`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;Tornado&amp;#39;s gzip decompression routines work in limited-size chunks, but have no overall limit for the total size of decompressed chunks that they will accumulate (There has always been a limit for the total *compressed* size). This allows a malicious server to consume effectively unlimited amounts of memory if it is accessed via SimpleAsyncHTTPClient in its default configuration. `HTTPServer` is not affected in its default configuration, but it is if `decompress_request=True` is set.&lt;/p&gt;
&lt;p&gt;This bug is fixed in Tornado 6.5.6. `max_body_size` is now checked both for the compressed and cumulative decompressed size of the response.&lt;/p&gt;
&lt;p&gt;Prior to upgrading, this issue can be mitigated by setting `decompress_response=False` or using `CurlAsyncHTTPClient`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-49855</guid>
    </item>
    <item>
      <title>EUVD-2026-338261</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-338261</link>
      <description>EUVD-2026-338261</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-338261</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49855</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49855</link>
      <description>&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49855</guid>
    </item>
    <item>
      <title>GHSA-mgf9-4vpg-hj56 — tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mgf9-4vpg-hj56</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;Tornado&amp;#39;s gzip decompression routines work in limited-size chunks, but have no overall limit for the total size of decompressed chunks that they will accumulate (There has always been a limit for the total *compressed* size). This allows a malicious server to consume effectively unlimited amounts of memory if it is accessed via SimpleAsyncHTTPClient in its default configuration. `HTTPServer` is not affected in its default configuration, but it is if `decompress_request=True` is set.&lt;/p&gt;
&lt;p&gt;This bug is fixed in Tornado 6.5.6. `max_body_size` is now checked both for the compressed and cumulative decompressed size of the response.&lt;/p&gt;
&lt;p&gt;Prior to upgrading, this issue can be mitigated by setting `decompress_response=False` or using `CurlAsyncHTTPClient`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;Tornado&amp;#39;s gzip decompression routines work in limited-size chunks, but have no overall limit for the total size of decompressed chunks that they will accumulate (There has always been a limit for the total *compressed* size). This allows a malicious server to consume effectively unlimited amounts of memory if it is accessed via SimpleAsyncHTTPClient in its default configuration. `HTTPServer` is not affected in its default configuration, but it is if `decompress_request=True` is set.&lt;/p&gt;
&lt;p&gt;This bug is fixed in Tornado 6.5.6. `max_body_size` is now checked both for the compressed and cumulative decompressed size of the response.&lt;/p&gt;
&lt;p&gt;Prior to upgrading, this issue can be mitigated by setting `decompress_response=False` or using `CurlAsyncHTTPClient`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mgf9-4vpg-hj56</guid>
    </item>
    <item>
      <title>OESA-2026-2727 — python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2727</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is an open source version of the scalable, non-blocking web server and tools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin. As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default. Beginning in Tornado 6.5.6, SimpleAsyncHTTPClient matches the default behavior of libcurl (and therefore CurlAsyncHTTPClient): When a redirect changes the scheme, host, or port of the url, the Authorization and Cookie headers will be removed when following the redirect.(CVE-2026-49853)&lt;/p&gt;
&lt;p&gt;SummaryTornado&amp;amp;apos;s optional native extension `tornado.speedups` implements `websocket_mask` without validating that the `mask` argument is exactly four bytes long. The C function reads four bytes from `mask` unconditionally, even when Python passes a shorter byte string. This can read beyond the provided buffer, exposing up to 3 bytes of uninitialized memory.The behavior is reachable from Tornado&amp;amp;apos;s XSRF token decoder when `xsrf_cookies=True` and the native extension is active. ### MitigationsThis bug is fixed in Tornado 6.5.6. Prior to upgrading to this version, setting the environment variable TORNADO_EXTENSION=0 will disable the vulnerable code (at the expe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is an open source version of the scalable, non-blocking web server and tools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin. As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default. Beginning in Tornado 6.5.6, SimpleAsyncHTTPClient matches the default behavior of libcurl (and therefore CurlAsyncHTTPClient): When a redirect changes the scheme, host, or port of the url, the Authorization and Cookie headers will be removed when following the redirect.(CVE-2026-49853)&lt;/p&gt;
&lt;p&gt;SummaryTornado&amp;amp;apos;s optional native extension `tornado.speedups` implements `websocket_mask` without validating that the `mask` argument is exactly four bytes long. The C function reads four bytes from `mask` unconditionally, even when Python passes a shorter byte string. This can read beyond the provided buffer, exposing up to 3 bytes of uninitialized memory.The behavior is reachable from Tornado&amp;amp;apos;s XSRF token decoder when `xsrf_cookies=True` and the native extension is active. ### MitigationsThis bug is fixed in Tornado 6.5.6. Prior to upgrading to this version, setting the environment variable TORNADO_EXTENSION=0 will disable the vulnerable code (at the expe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2727</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11027-1 — python311-tornado6-6.5.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11027-1</link>
      <description>&lt;p&gt;python311-tornado6-6.5.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-tornado6-6.5.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11027-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3389 — tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3389</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;Tornado&amp;#39;s gzip decompression routines work in limited-size chunks, but have no overall limit for the total size of decompressed chunks that they will accumulate (There has always been a limit for the total *compressed* size). This allows a malicious server to consume effectively unlimited amounts of memory if it is accessed via SimpleAsyncHTTPClient in its default configuration. `HTTPServer` is not affected in its default configuration, but it is if `decompress_request=True` is set.&lt;/p&gt;
&lt;p&gt;This bug is fixed in Tornado 6.5.6. `max_body_size` is now checked both for the compressed and cumulative decompressed size of the response.&lt;/p&gt;
&lt;p&gt;Prior to upgrading, this issue can be mitigated by setting `decompress_response=False` or using `CurlAsyncHTTPClient`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;Tornado&amp;#39;s gzip decompression routines work in limited-size chunks, but have no overall limit for the total size of decompressed chunks that they will accumulate (There has always been a limit for the total *compressed* size). This allows a malicious server to consume effectively unlimited amounts of memory if it is accessed via SimpleAsyncHTTPClient in its default configuration. `HTTPServer` is not affected in its default configuration, but it is if `decompress_request=True` is set.&lt;/p&gt;
&lt;p&gt;This bug is fixed in Tornado 6.5.6. `max_body_size` is now checked both for the compressed and cumulative decompressed size of the response.&lt;/p&gt;
&lt;p&gt;Prior to upgrading, this issue can be mitigated by setting `decompress_response=False` or using `CurlAsyncHTTPClient`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3389</guid>
    </item>
    <item>
      <title>RHSA-2026:73987 — Red Hat Security Advisory: RHOAI 3.3.7 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:73987</link>
      <description>&lt;p&gt;golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy keras: Keras: Arbitrary file write via path traversal in archive extraction utilities sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;golang: net/url: Memory exhaustion in query parameter parsing in net/url urllib3: urllib3 Streaming API improperly handles highly compressed data nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression undici: undici: Denial of Service via crafted WebSocket frame with large length undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter jupyter-server: jupyter-server: Sensitive data exposure via path traversal vulnerability fast-uri: fast-uri: Path traversal vulnerability allows bypass of security policies undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy keras: Keras: Arbitrary file write via path traversal in archive extraction utilities sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity guardrails-detectors: guardrails-detectors: Unauthenticated Regular-Expression…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:73987</guid>
    </item>
    <item>
      <title>RLSA-2026:67146 — Important: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67146</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67146</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22286-1 — Security update for python-tornado6</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22286-1</link>
      <description>&lt;p&gt;Security update for python-tornado6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-tornado6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22286-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-49855</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49855</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49855</guid>
    </item>
  </channel>
</rss>
