PT-2026-92037 · Tornado+1 · Tornado+1

·

CVE-2023-54397

·

Published

2023-08-14

·

Updated

2026-09-30

CVSS v4.0

9.0

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.3.3
Description Improper parsing of Content-Length headers and chunk lengths allows the acceptance of non-standard characters such as -, +, and . This occurs because the int constructor is used to parse these values in tornado/http1connection.py, which interprets these characters as valid integers. When deployed behind certain proxies that interpret these characters differently, an attacker can send crafted HTTP requests to bypass proxy validation and perform HTTP request smuggling. This issue is known to affect older versions of haproxy.
Recommendations Update to version 6.3.3 or later.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-54397
GHSA-QPPV-J76H-2RPX
OESA-2026-4034
OESA-2026-4035
OESA-2026-4036
OESA-2026-4037
SUSE-SU-2026:4403-1
SUSE-SU-2026:4404-1

Affected Products

Tornado
Haproxy