PT-2026-92038 · Tornado · Tornado

·

CVE-2024-14029

·

Published

2024-06-06

·

Updated

2026-09-28

CVSS v4.0

9.0

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.4.1
Description Tornado ignores duplicate Transfer-Encoding: chunked headers, which leads the server to treat requests as having no message body. Consequently, the chunked body is parsed as a subsequent request. When deployed behind proxies that forward requests containing multiple Transfer-Encoding: chunked headers, this inconsistency allows for HTTP request smuggling. This can result in access control bypass, cache poisoning, or connection desynchronization.
Recommendations Update Tornado to version 6.4.1 or later.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103101
CVE-2024-14029
GHSA-753J-MPMX-QQ6G
OESA-2026-4034
OESA-2026-4035
OESA-2026-4036
OESA-2026-4037

Affected Products

Tornado