Количество 8
Количество 8
CVE-2026-49854
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.
CVE-2026-49854
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.
CVE-2026-49854
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.
CVE-2026-49854
Tornado is a Python web framework and asynchronous networking library. ...
GHSA-cx3h-4qpv-8hc9
Tornado has out-of-bounds memory access via C extension
openSUSE-SU-2026:21067-1
Security update for python-tornado6
SUSE-SU-2026:2726-1
Security update for python-tornado
SUSE-SU-2026:2725-1
Security update for python-tornado6
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-49854 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6. | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
CVE-2026-49854 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6. | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
CVE-2026-49854 Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6. | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
CVE-2026-49854 Tornado is a Python web framework and asynchronous networking library. ... | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
GHSA-cx3h-4qpv-8hc9 Tornado has out-of-bounds memory access via C extension | CVSS3: 3.7 | 0% Низкий | около 2 месяцев назад | |
openSUSE-SU-2026:21067-1 Security update for python-tornado6 | около 1 месяца назад | |||
SUSE-SU-2026:2726-1 Security update for python-tornado | около 1 месяца назад | |||
SUSE-SU-2026:2725-1 Security update for python-tornado6 | около 1 месяца назад |
Уязвимостей на страницу