Description
Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.
Published: 2026-09-15
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: HTTP Request Smuggling
Action: Patch Now
AI Analysis

Impact

duplicate Transfer‑Encoding: chunked headers, treating a request as having no body and parsing the chunked body as an adjacent request. This bug is a classic HTTP request smuggling flaw (CWE-444) that compromises confidentiality, integrity, and availability of the service. Attackers can smuggle requests by sending crafted headers, which can lead to access control bypass, cache poisoning, or connection desynchronization.

Affected Systems

The affected product is the Tornado web framework (tornadoweb:tornado) with all releases older than 6.4.1. No finer version granularity is specified by the advisory.

Risk and Exploitability

The flaw carries a CVSS score of 9, signifying critical severity. The EPSS score is reported as <1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it from the external network by sending duplicate Transfer‑Encoding: chunked headers to a Tornado instance that sits behind a proxy; the server will interpret the first request’s body as a new request, potentially bypassing authentication, manipulating cached responses, or disrupting connections.

Generated by OpenCVE AI on September 20, 2026 at 16:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Tornado to version 6.4.1 or later.
  • Ensure proxies or load balancers strip or reject duplicate Transfer‑Encoding: chunked headers before forwarding requests to Tornado.
  • If upgrading immediately is not possible, configure Tornado to reject requests containing duplicate Transfer‑Encoding headers or use an external reverse proxy that normalizes headers before they reach Tornado.

Generated by OpenCVE AI on September 20, 2026 at 16:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.
Title Tornado before 6.4.1 HTTP Request Smuggling via Transfer-Encoding
First Time appeared Tornadoweb
Tornadoweb tornado
Weaknesses CWE-444
CPEs cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Vendors & Products Tornadoweb
Tornadoweb tornado
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N'}

cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N'}


Subscriptions

Tornadoweb Tornado
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T17:09:00.298Z

Reserved: 2026-03-23T19:30:06.622Z

Link: CVE-2024-14029

cve-icon Vulnrichment

Updated: 2026-09-15T17:08:25.927Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:06.893

Modified: 2026-09-28T14:10:00.213

Link: CVE-2024-14029

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T15:17:52Z

Links: CVE-2024-14029 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')