Merged
Merged
Conversation
This PR contains the following updates:
| Package | Change | Age | Confidence |
|---|---|---|---|
| tornado (source) | 6.5.4 โ 6.5.5 |
GitHub Vulnerability Alerts
GHSA-78cv-mqj4-43f7
Values passed to the domain, path, and samesite arguments of RequestHandler.set_cookie were not completely validated in versions of Tornado prior to 6.5.5. In particular, semicolons would be allowed, which could be used to inject attacker-controlled values for other cookie attributes.
Release Notes
tornadoweb/tornado (tornado)v6.5.5
Configuration
๐ Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
๐ฆ Automerge: Enabled.
โป Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
๐ Ignore: Close this PR and you won't be reminded about this update again.
- If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.
renovate Bot deleted the renovate/pypi-tornado-vulnerability branch
March 12, 2026 01:24