Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-91992

Опубликовано: 15 сент. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

EPSS

Процентиль: 11%
0.00206
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 дня назад

(Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)

CVSS3: 5.9
redhat
4 дня назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
debian
4 дня назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...

CVSS3: 5.9
github
4 дня назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

EPSS

Процентиль: 11%
0.00206
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-200