Security Advisory

CVE-2026-49854

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-14 20:43:03
Last updated 2026-07-15 13:26:39
Assigner GitHub_M
CVSS score 5.3
State PUBLISHED

Description

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.