UbuntuUpdates.org

Package "python3-tornado"

Name: python3-tornado

Description:

scalable, non-blocking web server and tools - Python 3 package

Latest version: 6.5.4-0.1ubuntu0.1
Release: resolute (26.04)
Level: updates
Repository: main
Head package: python-tornado
Homepage: https://www.tornadoweb.org/

Links


Download "python3-tornado"


Other versions of "python3-tornado" in Resolute

Repository Area Version
base main 6.5.4-0.1
security main 6.5.4-0.1ubuntu0.1

Changelog

Version: 6.5.4-0.1ubuntu0.1 2026-04-28 21:08:02 UTC

  python-tornado (6.5.4-0.1ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Denial of service when parsing large multipart bodies.
    - debian/patches/CVE-2026-31958.patch: Add limit of 100 parts and enforce
      checks in tornado/httputil.py. Add tests in
      tornado/test/httputil_test.py.
    - CVE-2026-31958
  * SECURITY UPDATE: Cookie attribute injection.
    - debian/patches/CVE-2026-35536.patch: Raise CookieError on invalid
      characters in tornado/web.py. Add tests in tornado/test/web_test.py.
    - CVE-2026-35536

 -- Hlib Korzhynskyy <email address hidden> Tue, 28 Apr 2026 14:38:37 -0230

CVE-2026-31958 Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts i
CVE-2026-35536 In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were n



About   -   Send Feedback to @ubuntu_updates