Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.
References
Configurations
No configuration.
History
17 Sep 2026, 16:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f - |
Information
Published : 2026-09-15 16:17
Updated : 2026-09-17 16:18
NVD link : CVE-2026-91992
Mitre link : CVE-2026-91992
CVE.ORG link : CVE-2026-91992
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
