Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 16:17
Updated : 2026-09-16 13:42
NVD link : CVE-2024-58384
Mitre link : CVE-2024-58384
CVE.ORG link : CVE-2024-58384
JSON object : View
Products Affected
No product.
CWE
CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
