UbuntuUpdates.org

Package "python-tornado"

Name: python-tornado

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • scalable, non-blocking web server and tools - documentation
  • scalable, non-blocking web server and tools - Python 3 package

Latest version: 6.5.4-0.1ubuntu0.1
Release: resolute (26.04)
Level: security
Repository: main

Links



Other versions of "python-tornado" in Resolute

Repository Area Version
base main 6.5.4-0.1
updates main 6.5.4-0.1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 6.5.4-0.1ubuntu0.1 2026-04-28 21:08:02 UTC

  python-tornado (6.5.4-0.1ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: Denial of service when parsing large multipart bodies.
    - debian/patches/CVE-2026-31958.patch: Add limit of 100 parts and enforce
      checks in tornado/httputil.py. Add tests in
      tornado/test/httputil_test.py.
    - CVE-2026-31958
  * SECURITY UPDATE: Cookie attribute injection.
    - debian/patches/CVE-2026-35536.patch: Raise CookieError on invalid
      characters in tornado/web.py. Add tests in tornado/test/web_test.py.
    - CVE-2026-35536

 -- Hlib Korzhynskyy <email address hidden> Tue, 28 Apr 2026 14:38:37 -0230

CVE-2026-31958 Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts i
CVE-2026-35536 In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were n



About   -   Send Feedback to @ubuntu_updates