Source: python-tornado Version: 6.5.5-5 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for python-tornado. CVE-2026-91990[0]: | Tornado before 6.5.8 contains a memory amplification vulnerability | in parse_multipart_form_data that splits multipart data before | validating the max_parts limit. Attackers can send crafted multipart | requests with many parts to create large transient lists, exhausting | server memory and causing denial of service. CVE-2026-91991[1]: | Tornado before 6.5.8 contains an incomplete fix for cookie attribute | injection that allows attackers to inject arbitrary cookie | attributes by passing capitalized or legacy keyword arguments to | set_cookie. Attackers can embed semicolon-delimited data in | capitalized parameters like Domain, Path, or SameSite to bypass | validation and modify cookie security attributes. CVE-2026-91992[2]: | Tornado before 6.5.7 contains a credential leak vulnerability in | CurlAsyncHTTPClient where pycurl handles are reused across requests | without proper state clearing. Attackers can obtain sensitive | credentials by issuing requests through the same client instance, | allowing TLS certificates or proxy authentication to persist across | unintended requests. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-91990 https://www.cve.org/CVERecord?id=CVE-2026-91990 [1] https://security-tracker.debian.org/tracker/CVE-2026-91991 https://www.cve.org/CVERecord?id=CVE-2026-91991 [2] https://security-tracker.debian.org/tracker/CVE-2026-91992 https://www.cve.org/CVERecord?id=CVE-2026-91992 Regards, Salvatore

