CVE-2026-91992

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.
Configurations

No configuration.

History

17 Sep 2026, 16:18

Type Values Removed Values Added
References () https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f - () https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f -

Information

Published : 2026-09-15 16:17

Updated : 2026-09-17 16:18


NVD link : CVE-2026-91992

Mitre link : CVE-2026-91992

CVE.ORG link : CVE-2026-91992


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor