CVE-2026-49854
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implem
CVSS
5.3
Medio
EPSS
0.3%
p27
KEV
—
Exploit Today
8
0-100
Publicado: 14 jul 2026 · Última mod.: 15 jul 2026 · CWE-126
0.3%EPSS · 30 días0.3%
2026-08-182026-09-14
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.
- github.comhttps://github.com/tornadoweb/tornado/commit/96dc88c2a05705287856b2cd6b4b4034f9a6aaac
- github.comhttps://github.com/tornadoweb/tornado/pull/3626
- github.comhttps://github.com/tornadoweb/tornado/releases/tag/v6.5.6
- github.comhttps://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-906103.3 BAJ1.9%
——1A vulnerability was found in GPAC up to f1219cde. This affects the function gf_svg_attributes_copy of the file scenegraph/svg_attributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.17hCVE-2026-76653—22.4%
——7A missing
authentication vulnerability in the VPN configuration management has been
identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker
may be able to access and modify VPN configuration information without valid
credentials.
Successful
exploitation may allow a remote unauthenticated attacker to disclose and modify
VPN configuration information.5dCVE-2026-839515.5 MED33.5%
——10Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.7dCVE-2026-839495.5 MED33.5%
——10Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.7dCVE-2026-813995.5 MED31.9%
——10Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.7dCVE-2026-785164.3 MED41.4%
——12Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.6d