StackRadar

CVE-2026-49853

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
103
of 17,781 indexed, latest versions
Container images
108
deployed by those charts
Fix available
1 of 2
affected packages

Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient

Carried by container images the latest versions of 103 of 17,781 indexed charts deploy, on 108 images.

Affected packageAffected versionsFixed inImages
tornadopypi2.4.1, 4.5.3, 5.1.1, 6.0.2+12 more6.5.6108
python-tornadodeb6.2.0-3+deb12u1no fix listed1
OSV records
DEBIAN-CVE-2026-49853GHSA-3x9g-8vmp-wqvf
Also known as
PYSEC-2026-3387

Charts affected

103 by stars
ChartLatestAffected imagesRadar Score
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-49853.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
tornado@6.0.2
6.5.6

Open the chart page →

9,347
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-49853.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
tornado@6.4.2
6.5.6

Open the chart page →

7,628
webapp-chartwebappchart1.0.01 of 1See more

webapp-chart webappchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-49853.

Container imageDigestPackageFixed in
amagdi888/my-repo:hello-appd8a10fc8faf6
tornado@5.1.1
6.5.6

Open the chart page →

1,201

Container images carrying it

108 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
tornado@6.5.4
6.5.6
1
quay.io/galaxyproject/galaxy-min:26.1.12c324c9789f5
tornado@6.5.5
6.5.6
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
tornado@6.5.5
6.5.6
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
tornado@6.3.3
6.5.6
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
tornado@6.5.5
6.5.6
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
tornado@6.2
6.5.6
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
tornado@6.4
6.5.6
1
registry.gitlab.com/crafty-controller/crafty-4:latest166a06f73d8c
tornado@6.5.4
6.5.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.