File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -4,6 +4,7 @@ Release notes
44.. toctree ::
55 :maxdepth: 2
66
7+ releases/v6.5.6
78 releases/v6.5.5
89 releases/v6.5.4
910 releases/v6.5.3
Original file line number Diff line number Diff line change 1+ What's new in Tornado 6.5.6
2+ ===========================
3+
4+ May 27, 2026
5+ ------------
6+
7+ Security fixes
8+ ~~~~~~~~~~~~~~
9+
10+ - ``SimpleAsyncHTTPClient `` now strips the ``Authorization `` and ``Cookie `` headers from the request
11+ when following a redirect to a different origin. This matches the default behavior of
12+ ``CurlAsyncHTTPClient ``. Applications that need different behavior here can set
13+ ``follow_redirects=False `` and handle redirects manually. Thanks to [Yannick
14+ Wang](https://github.com/noobone123) for being first to report this issue, as well as additional
15+ reporters [Kai Aizen](https://github.com/SnailSploit), [HunSec](https://github.com/0xHunSec), and
16+ [Thai Son Dinh](https://github.com/sondt99).
17+ - ``SimpleAsyncHTTPClient `` now enforces ``max_body_size `` on the decompressed size of the response,
18+ rather than the compressed size. This prevents a denial-of-service attack via a very large
19+ compressed response. Thanks to [Yuichiro Kedashiro](https://github.com/yuui25) for reporting this
20+ issue.
21+ - Fixed a bug in the C extension that could have read up to three bytes past the end of an input
22+ array. Thanks to [Thai Son Dinh](https://github.com/sondt99) for reporting this issue.
23+ - ``OpenIDMixin `` has improved parsing for the ``check_authentication `` response. Thanks to
24+ [Yannick Wang](https://github.com/noobone123) for reporting this issue.
25+
26+ Bug fixes
27+ ~~~~~~~~~
28+
29+ - ``CurlAsyncHTTPClient `` has been updated to use non-deprecated APIs, avoiding deprecation
30+ warnings with recent versions of ``pycurl ``.
Original file line number Diff line number Diff line change 2222# is zero for an official release, positive for a development branch,
2323# or negative for a release candidate or beta (after the base version
2424# number has been incremented)
25- version = "6.5.5 "
26- version_info = (6 , 5 , 5 , 0 )
25+ version = "6.5.6 "
26+ version_info = (6 , 5 , 6 , 0 )
2727
2828import importlib
2929import typing
You can’t perform that action at this time.
0 commit comments