Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.
CVSS Details
- CVSS 3.1 Base Score: 7.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade python-tornado-debuginfoUpgrade python3-tornado-debuginfoUpgrade python-tornadoUpgrade python-tornado-docUpgrade python3-tornadoUpgrade python3-tornado-doc | Aug 5, 2026 | Aug 5, 2026 |
| Amazon_linux_2023 | — | Upgrade python3.13-tornadoUpgrade python3.13-tornado-debugsourceUpgrade python3.13-tornado-docUpgrade python3-tornadoUpgrade python3.13-tornado-debuginfoUpgrade python-tornado-docUpgrade python3-tornado-debuginfoUpgrade python-tornado-debugsource | Aug 10, 2026 | Jul 14, 2026 |
| Redhat_linux | — | Upgrade python3-tornadoUpgrade python3-tornado-debuginfoNo solution existsUpgrade python-tornado-debugsource | Sep 1, 2026 | Jul 14, 2026 |
| Rocky_linux | — | Upgrade python3-tornadoUpgrade python3-tornado-debuginfoUpgrade python-tornado-debugsource | Sep 17, 2026 | Sep 15, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 6, 2026 | Jul 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub