mailarchive of the ptxdist mailing list
 help / color / mirror / Atom feed
* [ptxdist] [PATCH] python3-tornado: version bump 6.5.1 -> 6.5.5
@ 2026-04-17 10:27 Artur Wiebe via ptxdist
  0 siblings, 0 replies; only message in thread
From: Artur Wiebe via ptxdist @ 2026-04-17 10:27 UTC (permalink / raw)
  To: ptxdist; +Cc: Artur Wiebe

Changes between 6.5.1 and 6.5.5:
- 6.5.2: WebSocket ping interval fix, improved Host header handling,
  restored deprecated host argument on HTTPServerRequest, misc fixes.
- 6.5.3: Security fixes for CVE-2025-67724 (header injection/XSS in
  set_status reason), CVE-2025-67725 (DoS via repeated HTTP headers),
  CVE-2025-67726 (DoS via multipart/form-data parsing).
- 6.5.4: Restore case-insensitive "in" operator on HTTPHeaders
  (regression in 6.5.3).
- 6.5.5: Security fixes: limit multipart/form-data to 100 parts by
  default, validate cookie domain/path/samesite arguments, reject CR
  in multipart headers.

License unchanged (Apache-2.0).

Signed-off-by: Artur Wiebe <artur@4wiebe.de>
---
 rules/python3-tornado.make | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/rules/python3-tornado.make b/rules/python3-tornado.make
index b70b63654..d364ef668 100644
--- a/rules/python3-tornado.make
+++ b/rules/python3-tornado.make
@@ -11,8 +11,8 @@
 #
 PACKAGES-$(PTXCONF_PYTHON3_TORNADO) += python3-tornado
 
-PYTHON3_TORNADO_VERSION	:= 6.5.1
-PYTHON3_TORNADO_MD5	:= e3e3d74e2fedffacdacd8626d0c17a37
+PYTHON3_TORNADO_VERSION	:= 6.5.5
+PYTHON3_TORNADO_MD5	:= 765aacc9cb8931aa66c8f3a83050120c
 PYTHON3_TORNADO		:= tornado-$(PYTHON3_TORNADO_VERSION)
 PYTHON3_TORNADO_SUFFIX	:= tar.gz
 PYTHON3_TORNADO_URL	:= $(call ptx/mirror-pypi, tornado, $(PYTHON3_TORNADO).$(PYTHON3_TORNADO_SUFFIX))
-- 
2.53.0




^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-04-17 10:28 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-04-17 10:27 [ptxdist] [PATCH] python3-tornado: version bump 6.5.1 -> 6.5.5 Artur Wiebe via ptxdist

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox