[Git][security-tracker-team/security-tracker][master] Update status for new python-tornado issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 15 20:32:37 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d6ee8bcb by Salvatore Bonaccorso at 2026-09-15T21:32:16+02:00
Update status for new python-tornado issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -31,11 +31,16 @@ CVE-2026-91994 (Semaphore UI through 2.19.12 exempts GET and HEAD requests from
CVE-2026-91993 (Jpom through 2.11.12 fails to validate workspace ownership when resolv ...)
NOT-FOR-US: Jpom
CVE-2026-91992 (Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)
- TODO: check
+ - python-tornado <unfixed>
+ NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f
CVE-2026-91991 (Tornado before 6.5.8 contains an incomplete fix for cookie attribute i ...)
- TODO: check
+ - python-tornado <unfixed>
+ [trixie] - python-tornado <not-affected> (Incomplete fix for CVE-2026-35536 not applied)
+ NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-wwv5-g3v4-889x
+ NOTE: CVE exists because of an incomplete fix for CVE-2026-35536
CVE-2026-91990 (Tornado before 6.5.8 contains a memory amplification vulnerability in ...)
- TODO: check
+ - python-tornado <unfixed>
+ NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-8423-8fgw-73vq
CVE-2026-91989 (atomic-agents-stack before 1.1.0 contains a path traversal vulnerabili ...)
TODO: check
CVE-2026-91988 (atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the ...)
@@ -144580,6 +144585,7 @@ CVE-2026-35536 (In Tornado before 6.5.5, cookie attribute injection could occur
[trixie] - python-tornado <no-dsa> (Minor issue)
NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7
NOTE: Fixed by: https://github.com/tornadoweb/tornado/commit/24a2d96ea115f663b223887deb0060f13974c104 (v6.5.5)
+ NOTE: When fixing this issue make sure to make the fix complete and not open up CVE-2026-91991
CVE-2026-5046 (A flaw has been found in Tenda FH1201 1.2.0.14(408). Affected is the f ...)
NOT-FOR-US: Tenda
CVE-2026-5045 (A vulnerability was detected in Tenda FH1201 1.2.0.14(408). This impac ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6ee8bcbf21f70d4a86e8c63de196224f237a7c9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6ee8bcbf21f70d4a86e8c63de196224f237a7c9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/d537b303/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list