High severity7.7GHSA Advisory· Published Jul 14, 2026· Updated Jul 21, 2026
CVE-2026-49853
CVE-2026-49853
Description
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tornadoPyPI | < 6.5.6 | 6.5.6 |
Affected products
6- Range: < 6.5.6
- osv-coords5 versionspkg:apk/chainguard/mitmproxypkg:apk/wolfi/mitmproxypkg:pypi/tornadopkg:rpm/opensuse/python-tornado6&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-tornado6&distro=openSUSE%20Tumbleweed
< 12.2.3-r1+ 4 more
- (no CPE)range: < 12.2.3-r1
- (no CPE)range: < 12.2.3-r1
- (no CPE)range: < 6.5.6
- (no CPE)range: < 6.5-160000.5.1
- (no CPE)range: < 6.5.7-1.1
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-3x9g-8vmp-wqvfghsaADVISORY
- github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvfnvdWEB
- github.com/tornadoweb/tornado/commit/aba2569f7ed7a6bdbef816658fb6b7182531b751nvd
- github.com/tornadoweb/tornado/pull/3626nvd
- github.com/tornadoweb/tornado/releases/tag/v6.5.6nvd
News mentions
0No linked articles in our index yet.