{"cves":[{"id":"CVE-2026-49853","published":"2026-07-14T21:17:00","updated_at":"2026-07-16T10:53:55.672417+00:00","description":"\nTornado is a Python web framework and asynchronous networking library.\nPrior to 6.5.6, SimpleAsyncHTTPClient shallow-copied redirected requests\nand removed only the Host header, leaving Authorization, auth_username,\nauth_password, and auth_mode in place when a redirect changed scheme, host,\nor port. This issue is fixed in version 6.5.6.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49853","https://github.com/tornadoweb/tornado/commit/aba2569f7ed7a6bdbef816658fb6b7182531b751","https://github.com/tornadoweb/tornado/pull/3626","https://github.com/tornadoweb/tornado/releases/tag/v6.5.6","https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf"],"bugs":[""],"patches":{"python-tornado":[]},"tags":{},"packages":[{"name":"python-tornado","source":"https://ubuntu.com/security/cve?package=python-tornado","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-tornado","debian":"https://tracker.debian.org/pkg/python-tornado","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49477","published":"2026-07-14T21:17:00","updated_at":"2026-07-16T10:54:41.070484+00:00","description":"\nSoup Sieve is a CSS selector library designed to be used with Beautiful\nSoup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a\nregular expression vulnerable to catastrophic backtracking when processing\nan attribute selector with an unterminated quoted value in\nsoupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS\nselector strings to soupsieve.compile() or Beautiful Soup .select() /\n.select_one() to cause CPU exhaustion and denial of service. This issue is\nfixed in version 2.8.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49477","https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3","https://github.com/facelessuser/soupsieve/releases/tag/2.8.4","https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37"],"bugs":[""],"patches":{"soupsieve":[]},"tags":{},"packages":[{"name":"soupsieve","source":"https://ubuntu.com/security/cve?package=soupsieve","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=soupsieve","debian":"https://tracker.debian.org/pkg/soupsieve","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49476","published":"2026-07-14T21:17:00","updated_at":"2026-07-16T10:54:41.070484+00:00","description":"\nSoup Sieve is a CSS selector library designed to be used with Beautiful\nSoup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates\nunbounded memory when compiling large comma-separated selector lists,\nallowing an attacker who can supply a crafted selector string to\nsoupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate\nhundreds of megabytes of heap memory from a relatively small input and\ncause denial of service. This issue is fixed in version 2.8.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49476","https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39","https://github.com/facelessuser/soupsieve/releases/tag/2.8.4","https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x"],"bugs":[""],"patches":{"soupsieve":[]},"tags":{},"packages":[{"name":"soupsieve","source":"https://ubuntu.com/security/cve?package=soupsieve","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=soupsieve","debian":"https://tracker.debian.org/pkg/soupsieve","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49459","published":"2026-07-14T21:17:00","updated_at":"2026-07-16T10:54:18.822095+00:00","description":"\nDOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML,\nand SVG. Prior to 3.4.6, DOMPurify.sanitize(root, { IN_PLACE: true }) could\npreserve event-handler attributes on an attacker-controlled