Tornado 6.4.1 之前的版本中,CurlAsyncHTTPClient 存在 CRLF 注入漏洞,该漏洞未能拒绝请求头中的回车符(\r)和换行符(\n)。攻击者可以利用此漏洞在请求头的值中注入 CRLF 序列,从而注入任意头部信息,或构造全新的 HTTP 请求。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tornadoweb | tornado | < 6.4.1 |
affected |
6.4.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tornadoweb | tornado | 0 ~ 6.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-54397 | 7.5 HIGH | Tornado before 6.3.3 HTTP Request Smuggling via Content-Length |
| CVE-2026-91990 | 7.5 HIGH | Tornado before 6.5.8 Memory Amplification DoS via multipart |
| CVE-2024-14029 | 7.5 HIGH | Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding |
| CVE-2026-91992 | 5.9 MEDIUM | Tornado before 6.5.7 Credential Leak via Handle Reuse |
| CVE-2026-91991 | 5.4 MEDIUM | Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs |
No comments yet