Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqv5-7x9v-7j83

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.2
CVSS3: 5.9

Описание

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

EPSS

Процентиль: 11%
0.00206
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.9
ubuntu
5 дней назад

(Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)

CVSS3: 5.9
redhat
5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
nvd
5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
debian
5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...

EPSS

Процентиль: 11%
0.00206
Низкий

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-200