CVE-2026-49853High· 7.7▾ TwilightA flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially u…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.5%
Last analysed / modified upstream
A flaw was found in Tornado's SimpleAsyncHTTPClient. When following a redirect to a different origin, the client improperly retains and forwards sensitive authentication credentials, such as Authorization headers, to the new, potentially untrusted, destination. This vulnerability allows a remote attacker to gain unauthorized access to a user's credentials, leading to information disclosure.
tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-14.
Affected:
Fixed:
No fix planned:
Not affected:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67147 For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67146
Workarounds / mitigations:
follow_redirects=False when making HTTP requests. Manually handling redirects allows applications to ensure sensitive headers are not inadvertently sent to unintended origins. Disabling automatic redirects may alter application behavior that relies on this feature.Affected packages:
tornado < 6.5.6Patched in:
tornado 6.5.6Connected by shared product, vendor, weakness, or advisory.
CVE-2026-74945Medium· 6.5Information disclosure in the Graphics: Text component
CVE-2026-74948Medium· 6.5Information disclosure in the Graphics component
CVE-2026-74934High· 7.5Site isolation issue in the Graphics: CanvasWebGL component
CVE-2026-69249High· 7.5python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
CVE-2026-69248High· 7.4cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
CVE-2026-10051Medium· 5.3jetty: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051)