Количество 7
Количество 7
CVE-2026-49853
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.
CVE-2026-49853
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.
CVE-2026-49853
Tornado is a Python web framework and asynchronous networking library. ...
GHSA-3x9g-8vmp-wqvf
Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
openSUSE-SU-2026:21067-1
Security update for python-tornado6
SUSE-SU-2026:2726-1
Security update for python-tornado
SUSE-SU-2026:2725-1
Security update for python-tornado6
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-49853 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6. | CVSS3: 7.7 | 0% Низкий | 26 дней назад | |
CVE-2026-49853 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6. | CVSS3: 7.7 | 0% Низкий | 26 дней назад | |
CVE-2026-49853 Tornado is a Python web framework and asynchronous networking library. ... | CVSS3: 7.7 | 0% Низкий | 26 дней назад | |
GHSA-3x9g-8vmp-wqvf Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient | CVSS3: 7.7 | 0% Низкий | около 2 месяцев назад | |
openSUSE-SU-2026:21067-1 Security update for python-tornado6 | около 2 месяцев назад | |||
SUSE-SU-2026:2726-1 Security update for python-tornado | около 1 месяца назад | |||
SUSE-SU-2026:2725-1 Security update for python-tornado6 | около 1 месяца назад |
Уязвимостей на страницу