PT-2026-92106 · Pypi+1 · Pycurl+1

CVE-2026-91992

·

Published

2026-06-15

·

Updated

2026-09-25

CVSS v4.0

8.2

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.5.7
Description A credential leak exists in CurlAsyncHTTPClient because pycurl handles are reused across requests without properly clearing their state. This allows sensitive information set in one request to persist and be sent during a subsequent request using the same client instance.
Technical details include:
  • Vulnerable Component: The curl setup request function in tornado/curl httpclient.py fails to call curl.reset() before applying request options.
  • Credential Leak Vectors:
    • Client TLS certificates: The SSLCERT and SSLKEY variables are set but never cleared, causing certificates to be presented to unintended hosts.
    • Proxy Authentication: The PROXYUSERPWD variable may persist when a new proxy host is specified without new credentials, leaking basic-auth credentials to the new proxy.
    • Network Interface: The INTERFACE variable can persist, binding subsequent requests to an unintended network interface.
Recommendations Update Tornado to version 6.5.7 or later. As a temporary workaround, use a separate CurlAsyncHTTPClient instance for each distinct set of credentials (per client certificate or per proxy credential). As an alternative mitigation, use SimpleAsyncHTTPClient where applicable.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103098
CVE-2026-91992
GHSA-PW6J-QG29-8W7F
OESA-2026-4034
OESA-2026-4035
OESA-2026-4036
OESA-2026-4037

Affected Products

Tornado
Pycurl