HIGH7.7CVE-2026-49853Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient from 0
HIGH7.5CVE-2026-49855tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb) from 0
HIGH7.5CVE-2026-31958Tornado is vulnerable to DoS due to too many multipart parts from 0, < 6.1.0-1+deb11u4
HIGH7.5Tornado CRLF injection vulnerability
from 0, < 2.1.0-3
MEDIUM6.5python-tornado - security update
from 0, < 3.2.2-1
MEDIUM6.5python-tornado - security update
from 0, < 1.0.1-1+deb6u1
MEDIUM6.5python-tornado - security update
from 0, < 2.3-2+deb7u1
MEDIUM6.1python-tornado - security update
from 0, < 6.1.0-1+deb11u1
MEDIUM6.1python-tornado - security update
from 0, < 6.1.0-1+deb11u1
MEDIUM5.3Tornado has out-of-bounds memory access via C extension
from 0
—bzr - security update
from 0, < 2.4.1-3