Количество 7
Количество 7
CVE-2026-49855
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.
CVE-2026-49855
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.
CVE-2026-49855
Tornado is a Python web framework and asynchronous networking library. ...
GHSA-mgf9-4vpg-hj56
tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
openSUSE-SU-2026:21067-1
Security update for python-tornado6
SUSE-SU-2026:2726-1
Security update for python-tornado
SUSE-SU-2026:2725-1
Security update for python-tornado6
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-49855 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6. | CVSS3: 7.5 | 1% Низкий | 27 дней назад | |
CVE-2026-49855 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6. | CVSS3: 7.5 | 1% Низкий | 27 дней назад | |
CVE-2026-49855 Tornado is a Python web framework and asynchronous networking library. ... | CVSS3: 7.5 | 1% Низкий | 27 дней назад | |
GHSA-mgf9-4vpg-hj56 tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
openSUSE-SU-2026:21067-1 Security update for python-tornado6 | около 2 месяцев назад | |||
SUSE-SU-2026:2726-1 Security update for python-tornado | около 1 месяца назад | |||
SUSE-SU-2026:2725-1 Security update for python-tornado6 | около 1 месяца назад |
Уязвимостей на страницу