Skip to content

Commit a74240a

Browse files
committed
Release notes and version bump for 6.5.6.
1 parent e8fc7ed commit a74240a

3 files changed

Lines changed: 33 additions & 2 deletions

File tree

‎docs/releases.rst‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ Release notes
44
.. toctree::
55
:maxdepth: 2
66

7+
releases/v6.5.6
78
releases/v6.5.5
89
releases/v6.5.4
910
releases/v6.5.3

‎docs/releases/v6.5.6.rst‎

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
What's new in Tornado 6.5.6
2+
===========================
3+
4+
May 27, 2026
5+
------------
6+
7+
Security fixes
8+
~~~~~~~~~~~~~~
9+
10+
- ``SimpleAsyncHTTPClient`` now strips the ``Authorization`` and ``Cookie`` headers from the request
11+
when following a redirect to a different origin. This matches the default behavior of
12+
``CurlAsyncHTTPClient``. Applications that need different behavior here can set
13+
``follow_redirects=False`` and handle redirects manually. Thanks to [Yannick
14+
Wang](https://github.com/noobone123) for being first to report this issue, as well as additional
15+
reporters [Kai Aizen](https://github.com/SnailSploit), [HunSec](https://github.com/0xHunSec), and
16+
[Thai Son Dinh](https://github.com/sondt99).
17+
- ``SimpleAsyncHTTPClient`` now enforces ``max_body_size`` on the decompressed size of the response,
18+
rather than the compressed size. This prevents a denial-of-service attack via a very large
19+
compressed response. Thanks to [Yuichiro Kedashiro](https://github.com/yuui25) for reporting this
20+
issue.
21+
- Fixed a bug in the C extension that could have read up to three bytes past the end of an input
22+
array. Thanks to [Thai Son Dinh](https://github.com/sondt99) for reporting this issue.
23+
- ``OpenIDMixin`` has improved parsing for the ``check_authentication`` response. Thanks to
24+
[Yannick Wang](https://github.com/noobone123) for reporting this issue.
25+
26+
Bug fixes
27+
~~~~~~~~~
28+
29+
- ``CurlAsyncHTTPClient`` has been updated to use non-deprecated APIs, avoiding deprecation
30+
warnings with recent versions of ``pycurl``.

‎tornado/__init__.py‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -22,8 +22,8 @@
2222
# is zero for an official release, positive for a development branch,
2323
# or negative for a release candidate or beta (after the base version
2424
# number has been incremented)
25-
version = "6.5.5"
26-
version_info = (6, 5, 5, 0)
25+
version = "6.5.6"
26+
version_info = (6, 5, 6, 0)
2727

2828
import importlib
2929
import typing

0 commit comments

Comments
 (0)