Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92504.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92504
Upstream
Published
2026-07-14T21:17:02Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-49853 affecting package python-tornado 6.3.3-11
Details

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, authusername, authpassword, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.

References

Affected packages

Azure Linux:3 / python-tornado

Package

Name
python-tornado
Purl
pkg:rpm/azure-linux/python-tornado

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.3.3-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92504.json"