CVE-2026-49853

EUVD-2026-44503
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
7.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 29.19%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
tornadowebtornado
𝑥
< 6.5.6
CNA
Debian logo
Debian Releases
Debian Product
Codename
python-tornado
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-tornado
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python3-tornado
suse enterprise sap 15 SP4
4.5.3-150000.3.22.1
fixed
suse enterprise sap 15 SP5
4.5.3-150000.3.22.1
fixed
suse enterprise sap 15 SP6
4.5.3-150000.3.22.1
fixed
suse enterprise server 15 SP4
4.5.3-150000.3.22.1
fixed
suse enterprise server 15 SP5
4.5.3-150000.3.22.1
fixed
suse enterprise server 15 SP6
4.5.3-150000.3.22.1
fixed
python311-tornado6
suse enterprise desktop 15 SP7
6.3.2-150400.9.18.1
fixed
suse enterprise sap 15 SP4
6.3.2-150400.9.18.1
fixed
suse enterprise sap 15 SP5
6.3.2-150400.9.18.1
fixed
suse enterprise sap 15 SP6
6.3.2-150400.9.18.1
fixed
suse enterprise sap 15 SP7
6.3.2-150400.9.18.1
fixed
suse enterprise server 15 SP4
6.3.2-150400.9.18.1
fixed
suse enterprise server 15 SP5
6.3.2-150400.9.18.1
fixed
suse enterprise server 15 SP6
6.3.2-150400.9.18.1
fixed
suse enterprise server 15 SP7
6.3.2-150400.9.18.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-tornado
Amazon Linux 2
0:4.2.1-3.amzn2.0.6
fixed
python-tornado-debuginfo
Amazon Linux 2
0:4.2.1-3.amzn2.0.6
fixed
python-tornado-debugsource
Amazon Linux 2023
0:6.1.0-2.amzn2023.0.9
fixed
python-tornado-doc
Amazon Linux 2
0:4.2.1-3.amzn2.0.6
fixed
Amazon Linux 2023
0:6.1.0-2.amzn2023.0.9
fixed
python3-tornado
Amazon Linux 2
0:5.0.2-4.amzn2.0.9
fixed
Amazon Linux 2023
0:6.1.0-2.amzn2023.0.9
fixed
python3-tornado-debuginfo
Amazon Linux 2
0:5.0.2-4.amzn2.0.9
fixed
Amazon Linux 2023
0:6.1.0-2.amzn2023.0.9
fixed
python3-tornado-doc
Amazon Linux 2
0:5.0.2-4.amzn2.0.9
fixed
python3.13-tornado
Amazon Linux 2023
0:6.4.2-1.amzn2023.0.4
fixed
python3.13-tornado-debuginfo
Amazon Linux 2023
0:6.4.2-1.amzn2023.0.4
fixed
python3.13-tornado-debugsource
Amazon Linux 2023
0:6.4.2-1.amzn2023.0.4
fixed
python3.13-tornado-doc
Amazon Linux 2023
0:6.4.2-1.amzn2023.0.4
fixed