VDB

CVE-2026-49854

CVE-2026-49854 PUBLISHED CVSS 5.3 MEDIUM

Reported by GitHub_M · Published July 14, 2026

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.

Risk Scores

CVSS 3.1
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected Products

VendorProductVersions
tornadowebtornado< 6.5.6
chainguardairflow-30, 0, 0
chainguardlitellm0, 0, 0
chainguardtensorflow-gpu-jupyter0, 0, 0
wolfiairflow-30, 0, 0
tornadowebtornado< 6.5.6, < 6.5.6
chainguardmitmproxy0, 0, 0
chainguardtensorflow-cpu-jupyter0, 0, 0
wolfimitmproxy0, 0, 0

Timeline

  • Jun 12, 2026 CVE Published
  • Jul 15, 2026 Security Advisory
  • Jul 15, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 4, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›