VDB
CVE-2026-49854
CVE-2026-49854
PUBLISHED
CVSS 5.3 MEDIUM
Reported by GitHub_M · Published July 14, 2026
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.
Risk Scores
CVSS 3.1
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| tornadoweb | tornado | < 6.5.6 |
| chainguard | airflow-3 | 0, 0, 0 |
| chainguard | litellm | 0, 0, 0 |
| chainguard | tensorflow-gpu-jupyter | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| tornadoweb | tornado | < 6.5.6, < 6.5.6 |
| chainguard | mitmproxy | 0, 0, 0 |
| chainguard | tensorflow-cpu-jupyter | 0, 0, 0 |
| wolfi | mitmproxy | 0, 0, 0 |
Timeline
- Jun 12, 2026 CVE Published
- Jul 15, 2026 Security Advisory
- Jul 15, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
References
- https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9 x_refsource_CONFIRM
- https://github.com/tornadoweb/tornado/pull/3626 x_refsource_MISC
- https://github.com/tornadoweb/tornado/commit/96dc88c2a05705287856b2cd6b4b4034f9a6aaac x_refsource_MISC
- https://github.com/tornadoweb/tornado/releases/tag/v6.5.6 x_refsource_MISC