[ALSA-2026:67146] Important: python-tornado security update
Type:
security
Severity:
important
Release date:
2026-09-15
Description:
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * tornado: Tornado: Information disclosure via improper handling of credentials during HTTP redirects (CVE-2026-49853) * tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 python3-tornado-6.5.8-0.el9_8.1.aarch64.rpm 067812c18a0e54f1138e9686446f2cade5a9f7d087eaab5d7165be0d81f24593
ppc64le python3-tornado-6.5.8-0.el9_8.1.ppc64le.rpm 037e51e9f1dea4ba36a98d8bc7ed076357b5619acb990e392b8e700c188ec5bb
s390x python3-tornado-6.5.8-0.el9_8.1.s390x.rpm 107aa9fc2ffd293c1bdcf64fb703b665746c0cddba8468440389eeb88105eeef
x86_64 python3-tornado-6.5.8-0.el9_8.1.x86_64.rpm d56c8c961c68bcdf354a1463f39e4986cdbf25f5537a2d3a8a4c34467d9c03dd
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.