CVE-2026-49853: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in tornadoweb tornado
Tornado, a Python web framework, had a vulnerability prior to version 6.5.6 where the SimpleAsyncHTTPClient improperly handled HTTP redirects by shallow-copying requests and only removing the Host header. This caused sensitive headers such as Authorization, auth_username, auth_password, and auth_mode to be retained when redirects changed scheme, host, or port, potentially exposing sensitive information to unauthorized actors. The issue is fixed in Tornado version 6.5.6.
AI Analysis
Technical Summary
CVE-2026-49853 describes an information exposure vulnerability in Tornado's SimpleAsyncHTTPClient before version 6.5.6. When following HTTP redirects, the client shallow-copied the original request but only removed the Host header, leaving sensitive authentication headers intact even if the redirect changed the scheme, host, or port. This could lead to unauthorized disclosure of sensitive credentials or tokens. The vulnerability is addressed by properly clearing these headers in version 6.5.6.
Potential Impact
Sensitive authentication information such as Authorization headers and authentication credentials could be exposed to unintended hosts during HTTP redirects, potentially allowing unauthorized actors to access protected resources or credentials. The CVSS score of 7.7 (high severity) reflects the network attack vector, low attack complexity, and high confidentiality impact without integrity or availability impact.
Mitigation Recommendations
Upgrade Tornado to version 6.5.6 or later, where this vulnerability is fixed by properly removing sensitive headers on redirects that change scheme, host, or port. No other mitigation is indicated or required.
CVE-2026-49853: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in tornadoweb tornado
Description
Tornado, a Python web framework, had a vulnerability prior to version 6.5.6 where the SimpleAsyncHTTPClient improperly handled HTTP redirects by shallow-copying requests and only removing the Host header. This caused sensitive headers such as Authorization, auth_username, auth_password, and auth_mode to be retained when redirects changed scheme, host, or port, potentially exposing sensitive information to unauthorized actors. The issue is fixed in Tornado version 6.5.6.
CVSS v3.1
Score 7.7high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-49853 describes an information exposure vulnerability in Tornado's SimpleAsyncHTTPClient before version 6.5.6. When following HTTP redirects, the client shallow-copied the original request but only removed the Host header, leaving sensitive authentication headers intact even if the redirect changed the scheme, host, or port. This could lead to unauthorized disclosure of sensitive credentials or tokens. The vulnerability is addressed by properly clearing these headers in version 6.5.6.
Potential Impact
Sensitive authentication information such as Authorization headers and authentication credentials could be exposed to unintended hosts during HTTP redirects, potentially allowing unauthorized actors to access protected resources or credentials. The CVSS score of 7.7 (high severity) reflects the network attack vector, low attack complexity, and high confidentiality impact without integrity or availability impact.
Mitigation Recommendations
Upgrade Tornado to version 6.5.6 or later, where this vulnerability is fixed by properly removing sensitive headers on redirects that change scheme, host, or port. No other mitigation is indicated or required.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:11027-1
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-49854","CVE-2026-49855"]
- Cvss Version
- null
Threat ID: 6a2f1a531cccde5f2636f452
Added to database: 06/14/2026, 21:17:07 UTC
Last enriched: 07/22/2026, 20:59:09 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 127
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.