Description
Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Credential Disclosure
Action: Patch
AI Analysis

Impact

Tornado before version 6.5.7 allows credential leakage through its CurlAsyncHTTPClient component. Under the current implementation, pycurl handles are reused across multiple requests without clearing internal state, so TLS certificates and proxy authentication information can persist beyond their intended scope. As a result, an attacker who can send requests via the same client instance may capture sensitive credentials that were originally intended for an earlier request source.

Affected Systems

This flaw affects the Tornado web framework supplied by tornadoweb before the 6.5.7 release. No specific sub‑versions are listed beyond the general cutoff, so any deployment using Tornado 6.5.6 or older is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.2 classifies the vulnerability as high severity. The EPSS score of <1% indicates a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an attacker may cause an application to reuse a CurlAsyncHTTPClient instance across requests, either by interacting with the web service directly or by influencing the application’s internal logic. Once the same client instance is repeatedly used, credential data can leak between requests, resulting in confidential information disclosure.

Generated by OpenCVE AI on September 20, 2026 at 16:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Tornado to version 6.5.7 or later.
  • Modify the application code to create a new CurlAsyncHTTPClient instance for each distinct request or service context, avoiding reuse across unrelated requests.
  • If reusing a client instance is unavoidable, explicitly clear proxy authentication credentials and TLS session data after each request, or configure pycurl to disallow persistent authentication.

Generated by OpenCVE AI on September 20, 2026 at 16:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-524
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.
Title Tornado before 6.5.7 Credential Leak via Handle Reuse
First Time appeared Tornadoweb
Tornadoweb tornado
Weaknesses CWE-200
CPEs cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Vendors & Products Tornadoweb
Tornadoweb tornado
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Tornadoweb Tornado
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T15:16:30.401Z

Reserved: 2026-09-15T11:11:13.311Z

Link: CVE-2026-91992

cve-icon Vulnrichment

Updated: 2026-09-17T15:16:23.639Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:58.447

Modified: 2026-09-17T16:18:32.510

Link: CVE-2026-91992

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:33Z

Links: CVE-2026-91992 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-524

    Use of Cache Containing Sensitive Information