Loading market data...
← Back to CVE feed

CVE-2024-58384

MEDIUM CVSS 5.4 View on NVD ↗

Description

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Published: Sep 15, 2026 16:17 UTC Modified: Sep 15, 2026 16:17 UTC