CVE-2024-58384
Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.24%
- CWE
- CWE-113
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- tornadoweb tornado
- tornadoweb tornado
Weakness type
Related vulnerabilities
- CVE-2026-34520 — AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass
- CVE-2025-53007 — arduino-esp32 vulnerable to CRLF injection in WebServer.cpp
- CVE-2021-0268 — Junos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks.
- CVE-2024-52875 — An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE
- CVE-2025-61689 — HTTP.jl vulnerable to Header injection/Response splitting via header construction.
- CVE-2025-53094 — ESPAsyncWebServer Vulnerable to CRLF Injection in AsyncWebHeader.cpp
- CVE-2025-59151 — Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injection
- CVE-2026-67289 — FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection