Medium severity5.9NVD Advisory· Published Sep 15, 2026
CVE-2026-91992
CVE-2026-91992
Description
Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.5.7
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.