Loading market data...
← Back to CVE feed

CVE-2026-91992

MEDIUM CVSS 5.9 View on NVD ↗

Description

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Sep 15, 2026 16:17 UTC Modified: Sep 15, 2026 16:17 UTC