chiprook
← Security
SecurityOctober 2, 2026, 15:20

Tornado 6.5.9 fixes three flaws: symlinks, response size, query string

Three advisories published on 30 September 2026 cover Tornado: CVE-2026-8528 lets StaticFileHandler read files via symlinks outside the static root, CVE-2026-8529 leaves CurlAsyncHTTPClient without a response-size limit, and CVE-2026-8530 allows unbounded query-string arguments. All are fixed in 6.5.9; a separate advisory covers path traversal in GitPython.

Tornado 6.5.9 fixes three flaws: symlinks, response size, query string
#Tornado#GitPython
Read next
Security

GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient

Security

Urban VPN leaks DNS queries in plaintext, test finds

Security

Post-quantum key exchange proved unsecurable in 1,700 queries

Software

systemd mstack mounts overlays via symlinks, with caveats