Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-91992

Опубликовано: 15 сент. 2026
Источник: debian
EPSS Низкий

Описание

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-tornadounfixedpackage

Примечания

  • https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f

EPSS

Процентиль: 11%
0.00206
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
5 дней назад

(Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)

CVSS3: 5.9
redhat
5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
nvd
5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
github
5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

EPSS

Процентиль: 11%
0.00206
Низкий