tornadoweb / tornado

Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.
http://www.tornadoweb.org/
Apache License 2.0
21.76k stars 5.51k forks source link

Vulnerability: GHSA-753j-mpmx-qq6g #3392

Closed creat89 closed 5 months ago

creat89 commented 5 months ago

Hello!

Today my CVE checker told me that Tornado has a vulnerability. Here is a link to the description:

https://osv.dev/vulnerability/GHSA-753j-mpmx-qq6g

I'm creating this issue, so that everybody can track the progress on this issue.

creat89 commented 5 months ago

This was fixed in 6.4.1