Skip to content
Critical Vulnerabilities in Python-Tornado6 Affecting openSUSE and SUSE Systems

Critical Vulnerabilities in Python-Tornado6 Affecting openSUSE and SUSE Systems

First seen 30 Sep 2026, 22:30 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 23:29 UTC
  • •Four critical vulnerabilities in python-tornado6 disclosed, affecting openSUSE and SUSE systems.
  • •CVE-2023-54397 is rated critical with a CVSS of 9.0, allowing for HTTP request smuggling.
  • •Patches are available and should be applied immediately to prevent exploitation.

On September 30, 2026, multiple vulnerabilities were disclosed in python-tornado6, impacting openSUSE and SUSE systems. The vulnerabilities include CVE-2023-54397, a critical HTTP request smuggling flaw, and CVE-2026-91990, which allows for denial of service through resource exhaustion. Other issues include CVE-2024-58384, a CRLF injection vulnerability, and CVE-2026-91991, which permits cookie validation bypass. These vulnerabilities were published on September 15, 2026, with CVSS scores ranging from 6.3 to 9.0, indicating significant risk. Users are advised to apply patches immediately to mitigate the risks associated with these vulnerabilities. The updates can be installed using SUSE's recommended methods, including YaST and zypper patch.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-15
Vulnerabilities published
CVE-2023-54397, CVE-2024-58384, CVE-2026-91990, and CVE-2026-91991 were disclosed with varying severity ratings.
Linuxsecurity
2026-09-15
CVE-2026-91990 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
CVE-2024-58384 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
CVE-2026-91991 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-15
CVE-2023-54397 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-30
Patch released
SUSE released patches for python-tornado6 to address critical vulnerabilities. Users are urged to apply them immediately.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2023-54397 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of python-tornado are affected?
Versions of python-tornado prior to 6.3.3 are affected by these vulnerabilities.
What is the severity of CVE-2023-54397?
CVE-2023-54397 is rated critical with a CVSS score of 9.0, indicating a severe risk.
How can I apply the patches?
Patches can be applied using SUSE's recommended installation methods, such as YaST online_update or zypper patch.