Impact
duplicate Transfer‑Encoding: chunked headers, treating a request as having no body and parsing the chunked body as an adjacent request. This bug is a classic HTTP request smuggling flaw (CWE-444) that compromises confidentiality, integrity, and availability of the service. Attackers can smuggle requests by sending crafted headers, which can lead to access control bypass, cache poisoning, or connection desynchronization.
Affected Systems
The affected product is the Tornado web framework (tornadoweb:tornado) with all releases older than 6.4.1. No finer version granularity is specified by the advisory.
Risk and Exploitability
The flaw carries a CVSS score of 9, signifying critical severity. The EPSS score is reported as <1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it from the external network by sending duplicate Transfer‑Encoding: chunked headers to a Tornado instance that sits behind a proxy; the server will interpret the first request’s body as a new request, potentially bypassing authentication, manipulating cached responses, or disrupting connections.
OpenCVE Enrichment