Description
Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.
Published: 2026-09-15
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Request Smuggling
Action: Immediate Patch
AI Analysis

Impact

Tornado versions prior to 6.3.3 parse Content‑Length headers incorrectly, accepting non‑standard characters that enable HTTP request smuggling. The flaw allows an attacker to craft HTTP requests that bypass proxy validation and embed malicious requests after a legitimate one, potentially compromising request integrity and confidentiality. This weakness is classified as CWE‑444, reflecting improper handling of protocol information.

Affected Systems

Affected systems include the Tornado web framework from the TornadoWeb group, specifically any releases before 6.3.3. Organizations running these versions behind reverse proxies or other HTTP gateways are susceptible to the smuggling attack. No additional version granularity is listed beyond the overall pre‑6.3.3 range.

Risk and Exploitability

The CVSS score of 9 signals a high‑severity vulnerability, and the EPSS score of < 1% indicates a very low probability of exploitation in the wild. Nonetheless, the threat remains because HTTP request smuggling exploits rely on the attacker merely being able to send malicious requests to the vulnerable Tornado instance. The vulnerability is not listed in the CISA KEV catalog, but its impact is still substantial for deployments exposed to external networks. Exploitation requires only the ability to send HTTP requests with crafted Content‑Length headers to a vulnerable Tornado instance, so remote attackers can initiate the smuggling directly.

Generated by OpenCVE AI on September 20, 2026 at 16:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Tornado to version 6.3.3 or later, which removes the improper Content‑Length handling.
  • Verify that any reverse proxy or gateway in front of Tornado enforces strict compliance with RFC 7230, rejecting Content‑Length values that contain non‑standard characters.
  • Deploy network perimeter controls that filter or reject HTTP requests with invalid or non‑standard Content‑Length values before they reach the Tornado server.

Generated by OpenCVE AI on September 20, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Critical


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.
Title Tornado before 6.3.3 HTTP Request Smuggling via Content-Length
First Time appeared Tornadoweb
Tornadoweb tornado
Weaknesses CWE-444
CPEs cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Vendors & Products Tornadoweb
Tornadoweb tornado
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}

cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}


Subscriptions

Tornadoweb Tornado
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T14:48:55.089Z

Reserved: 2026-09-15T11:12:19.647Z

Link: CVE-2023-54397

cve-icon Vulnrichment

Updated: 2026-09-17T14:48:45.855Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:05.777

Modified: 2026-09-17T15:16:39.103

Link: CVE-2023-54397

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-15T15:17:52Z

Links: CVE-2023-54397 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')