Tornado 6.5.8 之前版本存在对 Cookie 属性注入漏洞的不完整修复。攻击者可通过向 方法传递大写或旧式关键字参数(如 、 、 )来注入任意 Cookie 属性。攻击者可以利用分号分隔的数据嵌入在这些大写参数中,从而绕过验证机制,篡改 Cookie 的安全属性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tornadoweb | tornado | 6.5.5< 6.5.8 |
affected |
6.5.8 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tornadoweb | tornado | 6.5.5 ~ 6.5.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-54397 | 7.5 HIGH | Tornado before 6.3.3 HTTP Request Smuggling via Content-Length |
| CVE-2026-91990 | 7.5 HIGH | Tornado before 6.5.8 Memory Amplification DoS via multipart |
| CVE-2024-14029 | 7.5 HIGH | Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding |
| CVE-2026-91992 | 5.9 MEDIUM | Tornado before 6.5.7 Credential Leak via Handle Reuse |
| CVE-2024-58384 | 5.4 MEDIUM | Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient |
No comments yet