Impact
Tornado versions prior to 6.3.3 parse Content‑Length headers incorrectly, accepting non‑standard characters that enable HTTP request smuggling. The flaw allows an attacker to craft HTTP requests that bypass proxy validation and embed malicious requests after a legitimate one, potentially compromising request integrity and confidentiality. This weakness is classified as CWE‑444, reflecting improper handling of protocol information.
Affected Systems
Affected systems include the Tornado web framework from the TornadoWeb group, specifically any releases before 6.3.3. Organizations running these versions behind reverse proxies or other HTTP gateways are susceptible to the smuggling attack. No additional version granularity is listed beyond the overall pre‑6.3.3 range.
Risk and Exploitability
The CVSS score of 9 signals a high‑severity vulnerability, and the EPSS score of < 1% indicates a very low probability of exploitation in the wild. Nonetheless, the threat remains because HTTP request smuggling exploits rely on the attacker merely being able to send malicious requests to the vulnerable Tornado instance. The vulnerability is not listed in the CISA KEV catalog, but its impact is still substantial for deployments exposed to external networks. Exploitation requires only the ability to send HTTP requests with crafted Content‑Length headers to a vulnerable Tornado instance, so remote attackers can initiate the smuggling directly.
OpenCVE Enrichment