Description
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: CRLF Header Injection via CurlAsyncHTTPClient
Action: Upgrade Framework
AI Analysis

Impact

Tornado versions prior to 6.4.1 contain a CRLF injection flaw in the CurlAsyncHTTPClient class. The flaw fails to reject carriage return and line feed characters that are embedded in request header values, enabling an attacker to inject arbitrary HTTP headers or construct entirely new HTTP requests. This weakness can lead to request smuggling, misrouting, or unintended downstream behavior and is classified as CWE-113 and CWE-93.

Affected Systems

The Tornado web framework, all releases older than 6.4.1, are affected. Any deployment that incorporates those earlier versions, and in particular code that forwards client-supplied header values to CurlAsyncHTTPClient, is vulnerable.

Risk and Exploitability

The CVSS base score of 6.3 indicates moderate severity. The EPSS score of <1% points to a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to control or supply header values to a CurlAsyncHTTPClient instance, which typically happens when an application forwards client headers to downstream services. Given the lack of widespread exploitation data, organizations should validate and filter header content.

Generated by OpenCVE AI on September 20, 2026 at 16:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Tornado to version 6.4.1 or later, which removes the CRLF injection flaw.
  • Restrict any header values passed through CurlAsyncHTTPClient to disallow carriage return and line feed characters, filtering or rejecting them before use.
  • Sanitize or encode externally supplied header values to ensure CRLF sequences are removed or escaped, in accordance with HTTP specifications.

Generated by OpenCVE AI on September 20, 2026 at 16:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-93
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
Title Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient
First Time appeared Tornadoweb
Tornadoweb tornado
Weaknesses CWE-113
CPEs cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Vendors & Products Tornadoweb
Tornadoweb tornado
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Tornadoweb Tornado
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T19:29:06.047Z

Reserved: 2026-08-16T13:02:14.691Z

Link: CVE-2024-58384

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:20.692Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:07.053

Modified: 2026-09-28T14:10:00.213

Link: CVE-2024-58384

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:17:53Z

Links: CVE-2024-58384 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-113

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')