CVE-2026-49853
tornadoweb tornado
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests and removed only the Host header, leaving Authorization, auth_username, auth_password, and auth_mode in place when a redirect changed scheme, host, or port. This issue is fixed in version 6.5.6.
- CVSS
- 7.7
- EPSS
- 0.36% 29.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.15