Credential Leak Vulnerability in Tornado by Tornado Web
CVE-2026-91992
8.2HIGH
What is CVE-2026-91992?
Tornado versions prior to 6.5.7 are affected by a severe vulnerability in the CurlAsyncHTTPClient that leads to a credential leak. This issue arises from the reuse of pycurl handles without proper state clearing between requests. Consequently, attackers can exploit this weakness to capture sensitive credentials, such as TLS certificates and proxy authentication details, by sending requests through the same client instance. It is crucial for users of affected Tornado versions to update promptly to mitigate this risk.
Affected Version(s)
tornado 0 < 6.5.7
tornado 6.5.7
