PT-2026-92106 · Pypi+1 · Pycurl+1
CVE-2026-91992
·
Published
2026-06-15
·
Updated
2026-09-25
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Tornado versions prior to 6.5.7
Description
A credential leak exists in
CurlAsyncHTTPClient because pycurl handles are reused across requests without properly clearing their state. This allows sensitive information set in one request to persist and be sent during a subsequent request using the same client instance.Technical details include:
- Vulnerable Component: The
curl setup requestfunction intornado/curl httpclient.pyfails to callcurl.reset()before applying request options. - Credential Leak Vectors:
- Client TLS certificates: The
SSLCERTandSSLKEYvariables are set but never cleared, causing certificates to be presented to unintended hosts. - Proxy Authentication: The
PROXYUSERPWDvariable may persist when a new proxy host is specified without new credentials, leaking basic-auth credentials to the new proxy. - Network Interface: The
INTERFACEvariable can persist, binding subsequent requests to an unintended network interface.
- Client TLS certificates: The
Recommendations
Update Tornado to version 6.5.7 or later.
As a temporary workaround, use a separate
CurlAsyncHTTPClient instance for each distinct set of credentials (per client certificate or per proxy credential).
As an alternative mitigation, use SimpleAsyncHTTPClient where applicable.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tornado
Pycurl