Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-49854

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.

A flaw was found in Tornado, a Python web framework. The optional native extension tornado.speedups did not properly validate the mask argument in its websocket_mask function. This allowed the C function to read beyond the intended buffer, potentially exposing up to three bytes of uninitialized memory. This vulnerability can be triggered when the native extension is active and Tornado's Cross-Site Request Forgery (XSRF) token decoder is in use, leading to information disclosure.

Отчет

This Moderate vulnerability in the Tornado web framework's optional native extension, tornado.speedups, could lead to information disclosure. When the native extension is active and the XSRF token decoder is in use, an out-of-bounds read of up to three bytes of uninitialized memory may occur. This limited data exposure is contingent on specific configurations and does not directly lead to broader system compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-bundleFix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Fix deferred
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2500661tornado: Tornado: Information disclosure via out-of-bounds read in websocket_mask

EPSS

Процентиль: 26%
0.00338
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
23 дня назад

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.

CVSS3: 5.3
nvd
23 дня назад

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.

CVSS3: 5.3
debian
23 дня назад

Tornado is a Python web framework and asynchronous networking library. ...

CVSS3: 3.7
github
около 2 месяцев назад

Tornado has out-of-bounds memory access via C extension

suse-cvrf
около 1 месяца назад

Security update for python-tornado6

EPSS

Процентиль: 26%
0.00338
Низкий

5.3 Medium

CVSS3