CVE-2026-49855 is a HIGH severity vulnerability in Tornado's gzip decompression routines. The issue allows a malicious server to consume effectively unlimited memory by processing limited-size chunks without enforcing an overall limit on accumulated decompressed chunks. This vulnerability is fixed in version 6.5.6. Users should review server configurations for SimpleAsyncHTTPClient or HTTPServer with deco [truncated]
CVE-2026-49853 is a HIGH severity vulnerability in Tornado's SimpleAsyncHTTPClient. Prior to version 6.5.6, the client shallow-copied redirected requests and removed only the Host header, leaving sensitive headers in place when a redirect changed scheme, host, or port. This issue allows potential exposure of sensitive information. Users should review their applications using SimpleAsyncHTTPClient and take [truncated]