MEDIUM 6.3 NVD
CVE-2024-58384
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request hea
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
References
- https://github.com/tornadoweb/tornado/security/advisories/GHSA-w235-7p84-xx57
- https://www.vulncheck.com/advisories/tornado-before-6.4.1-crlf-injection-via-curlasynchttp
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-09-15 via NVD.
vulnfeed aggregates 13549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.