PT-2026-49118 · Tornado · Tornado

CVE-2026-49853

·

Published

2026-06-13

·

Updated

2026-08-24

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.5.6
Description When SimpleAsyncHTTPClient follows a 3xx redirect, it shallow-copies the original HTTPRequest and removes only the Host header. It fails to clear the Authorization header, auth username, auth password, or auth mode when the redirect target changes origin. Consequently, credentials intended for one origin may be forwarded to a different origin when follow redirects is set to True.
Recommendations Update to version 6.5.6 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92504
CVE-2026-49853
ECHO-A103-FFDD-56F3
GHSA-3X9G-8VMP-WQVF
OESA-2026-2727
OESA-2026-2728
OPENSUSE-SU-2026:11027-1
OPENSUSE-SU-2026:21067-1
PYSEC-2026-3387
SUSE-SU-2026:22286-1
SUSE-SU-2026:22373-1
SUSE-SU-2026:22430-1
SUSE-SU-2026:22445-1
SUSE-SU-2026:2725-1
SUSE-SU-2026:2726-1
SUSE-SU-2026:3291-1

Affected Products

Tornado