Tornado是中国Tornado团队的一款异步网络编程框架。 Tornado 6.5.6之前版本存在缓冲区错误漏洞,该漏洞源于可选原生扩展tornado.speedups在实现websocket_mask时未验证mask参数是否为恰好四个字节,导致在启用原生扩展的情况下通过Tornado XSRF令牌解码时,C函数可能读取超过提供的缓冲区最多三个字节的内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tornadoweb | tornado | < 6.5.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tornadoweb | tornado | < 6.5.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49853 | 7.7 HIGH | Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPCl |
| CVE-2026-49855 | 7.5 HIGH | tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) |
No comments yet