CVE-2026-49854
MEDIUMTornado: Out-of-bounds memory access in C extension
Title source: cnaDescription
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9
X_Refsource_Misc x_refsource_misc
https://github.com/tornadoweb/tornado/pull/3626
X_Refsource_Misc x_refsource_misc
https://github.com/tornadoweb/tornado/commit/96dc88c2a05705287856b2cd6b4b4034f9a6aaac
X_Refsource_Misc x_refsource_misc
https://github.com/tornadoweb/tornado/releases/tag/v6.5.6
Scores
CVSS v3
5.3
EPSS
0.0034
EPSS Percentile
26.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-126
Status
published
Products (1)
tornadoweb/tornado
< 6.5.6
Published
Jul 14, 2026
Tracked Since
Jul 15, 2026