PT-2026-92037 · Tornado+1 · Tornado+1
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Tornado versions prior to 6.3.3
Description
Improper parsing of
Content-Length headers and chunk lengths allows the acceptance of non-standard characters such as -, +, and . This occurs because the int constructor is used to parse these values in tornado/http1connection.py, which interprets these characters as valid integers. When deployed behind certain proxies that interpret these characters differently, an attacker can send crafted HTTP requests to bypass proxy validation and perform HTTP request smuggling. This issue is known to affect older versions of haproxy.Recommendations
Update to version 6.3.3 or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tornado
Haproxy