This update for python-tornado fixes the following issues
CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395).
CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396).
CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397).
Affected Packages
python3-tornado
SUSE Linux Enterprise Desktop 15 SP7SUSE Linux Enterprise High Performance Computing 15 SP4SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOSSUSE Linux Enterprise High Performance Computing 15 SP4-LTSSSUSE Linux Enterprise High Performance Computing 15 SP5