CVE-2026-49854: CWE-126: Buffer Over-read in tornadoweb tornado
A buffer over-read vulnerability exists in the Tornado Python web framework's optional native extension tornado.speedups prior to version 6.5.6. The vulnerability occurs because the websocket_mask function does not validate that the mask argument is exactly four bytes, allowing up to three bytes to be read beyond the buffer during Tornado XSRF token decoding when the native extension is active. This issue is fixed in Tornado version 6.5.6.
AI Analysis
Technical Summary
CVE-2026-49854 is a buffer over-read vulnerability (CWE-126) in the Tornado web framework's optional native extension tornado.speedups. Specifically, the websocket_mask C function fails to validate that the mask argument is exactly four bytes long, which can cause it to read up to three bytes beyond the provided buffer. This occurs during Tornado XSRF token decoding when the native extension is enabled. The vulnerability affects Tornado versions prior to 6.5.6 and is resolved in version 6.5.6.
Potential Impact
The vulnerability allows an attacker to cause a buffer over-read, potentially exposing up to three bytes of memory beyond the intended buffer. According to the CVSS score of 5.3 (medium severity), the impact is limited to information disclosure (confidentiality loss) without integrity or availability impact. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade Tornado to version 6.5.6 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated. Patch status is confirmed by the vendor stating the fix is in version 6.5.6.
CVE-2026-49854: CWE-126: Buffer Over-read in tornadoweb tornado
Description
A buffer over-read vulnerability exists in the Tornado Python web framework's optional native extension tornado.speedups prior to version 6.5.6. The vulnerability occurs because the websocket_mask function does not validate that the mask argument is exactly four bytes, allowing up to three bytes to be read beyond the buffer during Tornado XSRF token decoding when the native extension is active. This issue is fixed in Tornado version 6.5.6.
CVSS v3.1
Score 5.3medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-49854 is a buffer over-read vulnerability (CWE-126) in the Tornado web framework's optional native extension tornado.speedups. Specifically, the websocket_mask C function fails to validate that the mask argument is exactly four bytes long, which can cause it to read up to three bytes beyond the provided buffer. This occurs during Tornado XSRF token decoding when the native extension is enabled. The vulnerability affects Tornado versions prior to 6.5.6 and is resolved in version 6.5.6.
Potential Impact
The vulnerability allows an attacker to cause a buffer over-read, potentially exposing up to three bytes of memory beyond the intended buffer. According to the CVSS score of 5.3 (medium severity), the impact is limited to information disclosure (confidentiality loss) without integrity or availability impact. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade Tornado to version 6.5.6 or later, where this vulnerability is fixed. No other mitigation or temporary workaround is indicated. Patch status is confirmed by the vendor stating the fix is in version 6.5.6.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-01T22:03:19.640Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a56a08668715ace432de5e4
Added to database: 07/14/2026, 20:48:06 UTC
Last enriched: 07/21/2026, 22:44:46 UTC
Last updated: 08/26/2026, 22:52:11 UTC
Views: 93
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.