Impact
Tornado before version 6.5.7 allows credential leakage through its CurlAsyncHTTPClient component. Under the current implementation, pycurl handles are reused across multiple requests without clearing internal state, so TLS certificates and proxy authentication information can persist beyond their intended scope. As a result, an attacker who can send requests via the same client instance may capture sensitive credentials that were originally intended for an earlier request source.
Affected Systems
This flaw affects the Tornado web framework supplied by tornadoweb before the 6.5.7 release. No specific sub‑versions are listed beyond the general cutoff, so any deployment using Tornado 6.5.6 or older is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.2 classifies the vulnerability as high severity. The EPSS score of <1% indicates a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an attacker may cause an application to reuse a CurlAsyncHTTPClient instance across requests, either by interacting with the web service directly or by influencing the application’s internal logic. Once the same client instance is repeatedly used, credential data can leak between requests, resulting in confidential information disclosure.
OpenCVE Enrichment