CVE Tools

Three Tornado Security Vulnerabilities Patched in Version 6.5.6

Daily CyberSecurity (securityonline.info)By Do Son

PatchTornado (Python web framework)

Our summary

Tornado maintainers have released version 6.5.6 to patch three security issues in the Python web framework, including CVE-2026-49853, CVE-2026-49855, and CVE-2026-49854. CVE-2026-49853 (7.7) can leak Authorization headers when SimpleAsyncHTTPClient follows redirects to a different origin, potentially exposing credentials across sites. CVE-2026-49855 (7.5) addresses a gzip bomb that could exhaust memory, while CVE-2026-49854 (5.3) fixes an out-of-bounds read in Tornado’s optional native extension that could reveal small amounts of uninitialized memory. Upgrading to Tornado 6.5.6 is the recommended mitigation, especially to address the credential-leak risk.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store