Impact
Tornado versions prior to 6.4.1 contain a CRLF injection flaw in the CurlAsyncHTTPClient class. The flaw fails to reject carriage return and line feed characters that are embedded in request header values, enabling an attacker to inject arbitrary HTTP headers or construct entirely new HTTP requests. This weakness can lead to request smuggling, misrouting, or unintended downstream behavior and is classified as CWE-113 and CWE-93.
Affected Systems
The Tornado web framework, all releases older than 6.4.1, are affected. Any deployment that incorporates those earlier versions, and in particular code that forwards client-supplied header values to CurlAsyncHTTPClient, is vulnerable.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity. The EPSS score of <1% points to a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to control or supply header values to a CurlAsyncHTTPClient instance, which typically happens when an application forwards client headers to downstream services. Given the lack of widespread exploitation data, organizations should validate and filter header content.
OpenCVE Enrichment