Tornado 6.5.7 之前的版本中,CurlAsyncHTTPClient 存在一个凭据泄露漏洞:pycurl 句柄在多个请求之间被复用,但并未进行适当的状态清除。攻击者可以通过同一个客户端实例发起请求,导致 TLS 证书或代理认证信息在非预期请求中持续存在,从而获取敏感凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tornadoweb | tornado | 0 ~ 6.5.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-54397 | 7.5 HIGH | Tornado before 6.3.3 HTTP Request Smuggling via Content-Length |
| CVE-2026-91990 | 7.5 HIGH | Tornado before 6.5.8 Memory Amplification DoS via multipart |
| CVE-2024-14029 | 7.5 HIGH | Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding |
| CVE-2026-91991 | 5.4 MEDIUM | Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs |
| CVE-2024-58384 | 5.4 MEDIUM | Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient |
No comments yet