Beveiligingsadvies

CVE-2026-49854

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-14 20:43:03
Laatst bijgewerkt 2026-07-15 13:26:39
Toegewezen door GitHub_M
CVSS-score 5.3
Status PUBLISHED

Beschrijving

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.