<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:25:41 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67146 — Important: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67146</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
  * tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: python3-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)
  * tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67146</guid>
    </item>
    <item>
      <title>BREW-jupyterlab-CVE-2026-49853 — Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient</title>
      <link>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-49853</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.&lt;/p&gt;
&lt;p&gt;As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.&lt;/p&gt;
&lt;p&gt;Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.&lt;/p&gt;
&lt;p&gt;As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.&lt;/p&gt;
&lt;p&gt;Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-49853</guid>
    </item>
    <item>
      <title>EUVD-2026-339157</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339157</link>
      <description>EUVD-2026-339157</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339157</guid>
    </item>
    <item>
      <title>fkie_cve-2026-49853</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-49853</link>
      <description>&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-49853</guid>
    </item>
    <item>
      <title>GHSA-3x9g-8vmp-wqvf — Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-3x9g-8vmp-wqvf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.&lt;/p&gt;
&lt;p&gt;As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.&lt;/p&gt;
&lt;p&gt;Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.&lt;/p&gt;
&lt;p&gt;As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.&lt;/p&gt;
&lt;p&gt;Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-3x9g-8vmp-wqvf</guid>
    </item>
    <item>
      <title>OESA-2026-2727 — python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2727</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is an open source version of the scalable, non-blocking web server and tools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin. As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default. Beginning in Tornado 6.5.6, SimpleAsyncHTTPClient matches the default behavior of libcurl (and therefore CurlAsyncHTTPClient): When a redirect changes the scheme, host, or port of the url, the Authorization and Cookie headers will be removed when following the redirect.(CVE-2026-49853)&lt;/p&gt;
&lt;p&gt;SummaryTornado&amp;amp;apos;s optional native extension `tornado.speedups` implements `websocket_mask` without validating that the `mask` argument is exactly four bytes long. The C function reads four bytes from `mask` unconditionally, even when Python passes a shorter byte string. This can read beyond the provided buffer, exposing up to 3 bytes of uninitialized memory.The behavior is reachable from Tornado&amp;amp;apos;s XSRF token decoder when `xsrf_cookies=True` and the native extension is active. ### MitigationsThis bug is fixed in Tornado 6.5.6. Prior to upgrading to this version, setting the environment variable TORNADO_EXTENSION=0 will disable the vulnerable code (at the expe…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is an open source version of the scalable, non-blocking web server and tools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin. As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default. Beginning in Tornado 6.5.6, SimpleAsyncHTTPClient matches the default behavior of libcurl (and therefore CurlAsyncHTTPClient): When a redirect changes the scheme, host, or port of the url, the Authorization and Cookie headers will be removed when following the redirect.(CVE-2026-49853)&lt;/p&gt;
&lt;p&gt;SummaryTornado&amp;amp;apos;s optional native extension `tornado.speedups` implements `websocket_mask` without validating that the `mask` argument is exactly four bytes long. The C function reads four bytes from `mask` unconditionally, even when Python passes a shorter byte string. This can read beyond the provided buffer, exposing up to 3 bytes of uninitialized memory.The behavior is reachable from Tornado&amp;amp;apos;s XSRF token decoder when `xsrf_cookies=True` and the native extension is active. ### MitigationsThis bug is fixed in Tornado 6.5.6. Prior to upgrading to this version, setting the environment variable TORNADO_EXTENSION=0 will disable the vulnerable code (at the expe…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2727</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11027-1 — python311-tornado6-6.5.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11027-1</link>
      <description>&lt;p&gt;python311-tornado6-6.5.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python311-tornado6-6.5.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11027-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3387 — Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3387</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.&lt;/p&gt;
&lt;p&gt;As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.&lt;/p&gt;
&lt;p&gt;Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest, rewrites the URL, decrements max_redirects, and removes only the Host header. It does not clear Authorization, auth_username, auth_password, or auth_mode when the redirect target changes origin.&lt;/p&gt;
&lt;p&gt;As a result, credentials intended for one origin can be forwarded to a different origin when follow_redirects=True, which is the default.&lt;/p&gt;
&lt;p&gt;Beginning in Tornado 6.5.6, `SimpleAsyncHTTPClient` matches the default behavior of `libcurl` (and therefore `CurlAsyncHTTPClient`): When a redirect changes the scheme, host, or port of the url, the `Authorization` and `Cookie` headers will be removed when following the redirect.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3387</guid>
    </item>
    <item>
      <title>RLSA-2026:67146 — Important: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67146</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: python-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853)&lt;/p&gt;
&lt;p&gt;* tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67146</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:22286-1 — Security update for python-tornado6</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:22286-1</link>
      <description>&lt;p&gt;Security update for python-tornado6&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-tornado6&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:22286-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-49853</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49853</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-49853</guid>
    </item>
  </channel>
</rss>
