PT-2026-92038 · Tornado · Tornado
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Tornado versions prior to 6.4.1
Description
Tornado ignores duplicate
Transfer-Encoding: chunked headers, which leads the server to treat requests as having no message body. Consequently, the chunked body is parsed as a subsequent request. When deployed behind proxies that forward requests containing multiple Transfer-Encoding: chunked headers, this inconsistency allows for HTTP request smuggling. This can result in access control bypass, cache poisoning, or connection desynchronization.Recommendations
Update Tornado to version 6.4.1 or later.
Exploit
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tornado