Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49854— Tornado: Out-of-bounds memory access in C extension

Quick assessment

Affected
tornadoweb tornado
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tornado是中国Tornado团队的一款异步网络编程框架。 Tornado 6.5.6之前版本存在缓冲区错误漏洞,该漏洞源于可选原生扩展tornado.speedups在实现websocket_mask时未验证mask参数是否为恰好四个字节,导致在启用原生扩展的情况下通过Tornado XSRF令牌解码时,C函数可能读取超过提供的缓冲区最多三个字节的内容。

CVSS 5.3 · Medium EPSS 0.34% · P27

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 1

VendorProduct Version RangeStatus
tornadoweb tornado < 6.5.6 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49854

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tornado: Out-of-bounds memory access in C extension
Source: CVE Program / CVE List V5
Vulnerability Description
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
缓冲区上溢读取
Source: CVE Program / CVE List V5
Vulnerability Title
Tornado 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tornado是中国Tornado团队的一款异步网络编程框架。 Tornado 6.5.6之前版本存在缓冲区错误漏洞,该漏洞源于可选原生扩展tornado.speedups在实现websocket_mask时未验证mask参数是否为恰好四个字节,导致在启用原生扩展的情况下通过Tornado XSRF令牌解码时,C函数可能读取超过提供的缓冲区最多三个字节的内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
tornadoweb tornado < 6.5.6 -

II. Public POCs for CVE-2026-49854

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49854

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49854 (2)

Vendor Advisories for CVE-2026-49854 (1)

Vendor Pages for CVE-2026-49854 (1)

Same Patch Batch · tornadoweb · 2026-07-14 · 3 CVEs total

CVE-2026-49853 7.7 HIGH Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPCl
CVE-2026-49855 7.5 HIGH tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)

IV. Related Vulnerabilities

V. Comments for CVE-2026-49854

No comments yet


Leave a comment