Linuxsecurity Critical Vulnerabilities in Python-Tornado6 Affecting openSUSE and SUSE Systems
Article Content
- •Four critical vulnerabilities in python-tornado6 disclosed, affecting openSUSE and SUSE systems.
- •CVE-2023-54397 is rated critical with a CVSS of 9.0, allowing for HTTP request smuggling.
- •Patches are available and should be applied immediately to prevent exploitation.
On September 30, 2026, multiple vulnerabilities were disclosed in python-tornado6, impacting openSUSE and SUSE systems. The vulnerabilities include CVE-2023-54397, a critical HTTP request smuggling flaw, and CVE-2026-91990, which allows for denial of service through resource exhaustion. Other issues include CVE-2024-58384, a CRLF injection vulnerability, and CVE-2026-91991, which permits cookie validation bypass. These vulnerabilities were published on September 15, 2026, with CVSS scores ranging from 6.3 to 9.0, indicating significant risk. Users are advised to apply patches immediately to mitigate the risks associated with these vulnerabilities. The updates can be installed using SUSE's recommended methods, including YaST and zypper patch.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2023-54397 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of python-tornado are affected?
What is the severity of CVE-2023-54397?
How can I apply the patches?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…