Tornado 6.5.9 fixes three flaws: symlinks, response size, query string
Three advisories published on 30 September 2026 cover Tornado: CVE-2026-8528 lets StaticFileHandler read files via symlinks outside the static root, CVE-2026-8529 leaves CurlAsyncHTTPClient without a response-size limit, and CVE-2026-8530 allows unbounded query-string arguments. All are fixed in 6.5.9; a separate advisory covers path traversal in GitPython.
- CVE-2026-8528: os.path.abspath does not resolve symlinks, exposing files outside static root
- CVE-2026-8529: CurlAsyncHTTPClient has no response-size cap, risking decompression bombs
- CVE-2026-8530: unbounded query-string argument count stalls the event loop
- Fix is upgrading to Tornado 6.5.9; GitPython affected by a separate advisory
Read next
Security