-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Mon, 05 Jan 2026 13:12:01 +0200
Source: python-tornado
Architecture: source
Version: 6.5.4-0.1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Adrian Bunk <bunk@debian.org>
Closes: 1122660 1122661 1122663
Changes:
python-tornado (6.5.4-0.1) unstable; urgency=medium
.
* Non-maintainer upload.
* New upstream release.
- CVE-2025-67724: Header injection and XSS via reason argument.
(Closes: #1122660)
- CVE-2025-67725: Quadratic DoS via Repeated Header Coalescing.
(Closes: #1122661)
- CVE-2025-67726: Quadratic DoS via Crafted Multipart Parameters.
(Closes: #1122663)
Checksums-Sha1:
c2022a276961ea81569467b75843c51d7568526a 2449 python-tornado_6.5.4-0.1.dsc
6523109ebb1b064da3bc79639259d9f1f326b0c7 544183 python-tornado_6.5.4.orig.tar.gz
597a136a5d52c20584384965904a812188e79eb6 10852 python-tornado_6.5.4-0.1.debian.tar.xz
Checksums-Sha256:
79bcf12c1e9cb008ae09a312efd9409f3370816d941d8c47095a516a43876895 2449 python-tornado_6.5.4-0.1.dsc
983f151603e388932ec2b6f5e0f5231c95d1ac8d1ac28fca834c0962ff9369e1 544183 python-tornado_6.5.4.orig.tar.gz
9cb862cc5420fa2e09cf3a2a6761fd2d0b094bbb57007146e51390f4c459053c 10852 python-tornado_6.5.4-0.1.debian.tar.xz
Files:
224ab98071b8e150aaba8378031a0194 2449 web optional python-tornado_6.5.4-0.1.dsc
6fffedfe64e08eb94532df3079fd79fe 544183 web optional python-tornado_6.5.4.orig.tar.gz
b997dbb20cfc757d2a9d5642fb060233 10852 web optional python-tornado_6.5.4-0.1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmlboHAACgkQiNJCh6LY
mLGqbA/8CSGx7WPzReOM0+PAQQTbAwoa3gvEy/o1jDmR3e6cPvvjjPDCkFc3+TaW
qwjVWX+OLKoO/hv1Ra+7yThUDxKZJsuDQ6KrR/zsvySCjD7WBrrTRNzOw1ujMUqn
e209UF496bHvdBL/YX/cQzoLWeno+SWMOHBeH/zKZZpT1EdlUnNyWK1y8W+SA0bP
5OPIGhXVJoGMa6DlKQrsqZtsOw4rXza8LVZFbhwcEaEeI+r5YNIDUkLZ1y3gAxU3
A8gLUiXEo9xHTSzO/X6UWlywRx0nmU+iotTXBpD4Ba2gjzZF+OxtUKxsPCJuSqIp
4VGozKa76YcgBN4x3qHEs60bEsJ+sV482utnfEhKlkalDie8ICe7/Oes+QUPiIgb
vICfqOxYtjYnWEwVkIyd3eZvs1kiHawKgtEkoWoJ7w5+oDVaYG1LeHlKvwbBMI9G
lvnbKRizrXZ7ESCAjfTtRIXq9gmSBMJkKrtc3VupxUSPWM0OjW1KCJa2DBLDJGAT
YEv2oPRRNqMHJ1EMpYFbMi2Va7YM0XK86K7D2yKGO9IvsiYajsoy6HuazhaW6hli
0G3PCpNbFzElJlXX4WAw53SJnU7mbKFHfhSSaj+gQUaHo3+KCo7mWy1ADwSovnwy
2LrlQpbhaDXxf1r9Xphd43RvYZUK1DpYYfJq4MjFFcAwClp9mf0=
=/jHX
-----END PGP SIGNATURE-----
Attachment:
pgpbHJdMkp8ja.pgp
Description: PGP signature