HTTP Request Smuggling in Tornado Web Framework by Tornado
CVE-2024-14029

9CRITICAL

Key Information:

Vendor

Tornadoweb

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2024-14029?

The Tornado Web Framework versions prior to 6.4.1 have a vulnerability where duplicate Transfer-Encoding: chunked headers are improperly handled. This mismanagement results in the framework disregarding the existence of a message body and misinterpreting the chunked body as an additional request. Attackers can exploit this flaw, particularly when Tornado operates behind proxies, to execute an HTTP request smuggling attack. This exploitation could lead to various security issues, including unauthorized access control bypass, cache poisoning risks, and connection desynchronization, threatening the overall integrity and security of the application.

Affected Version(s)

tornado 0 < 6.4.1

tornado 6.4.1

References

CVSS V4

Score:
9
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kenballus
.