What’s new in Tornado 6.5.6
May 27, 2026
Security fixes
SimpleAsyncHTTPClientnow strips theAuthorizationandCookieheaders from the request when following a redirect to a different origin. This matches the default behavior ofCurlAsyncHTTPClient. Applications that need different behavior here can setfollow_redirects=Falseand handle redirects manually. Thanks to [Yannick Wang](https://github.com/noobone123) for being first to report this issue, as well as additional reporters [Kai Aizen](https://github.com/SnailSploit), [HunSec](https://github.com/0xHunSec), and [Thai Son Dinh](https://github.com/sondt99).SimpleAsyncHTTPClientnow enforcesmax_body_sizeon the decompressed size of the response, rather than the compressed size. This prevents a denial-of-service attack via a very large compressed response. Thanks to [Yuichiro Kedashiro](https://github.com/yuui25) for reporting this issue.Fixed a bug in the C extension that could have read up to three bytes past the end of an input array. Thanks to [Thai Son Dinh](https://github.com/sondt99) for reporting this issue.
OpenIDMixinhas improved parsing for thecheck_authenticationresponse. Thanks to [Yannick Wang](https://github.com/noobone123) for reporting this issue.
Bug fixes
CurlAsyncHTTPClienthas been updated to use non-deprecated APIs, avoiding deprecation warnings with recent versions ofpycurl.