VYPR
Medium severity5.4NVD Advisory· Published Sep 15, 2026

CVE-2024-58384

CVE-2024-58384

Description

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.

Affected products

2
  • Tornadoweb/Tornadollm-fuzzy2 versions
    <6.4.1+ 1 more
    • (no CPE)range: <6.4.1
    • (no CPE)range: <6.4.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.