Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-91992

5 дней назад

(Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-91992

5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-91992

5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-91992

5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-jqv5-7x9v-7j83

5 дней назад

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-91992

(Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)

CVSS3: 5.9
0%
Низкий
5 дней назад
redhat логотип
CVE-2026-91992

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
0%
Низкий
5 дней назад
nvd логотип
CVE-2026-91992

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
0%
Низкий
5 дней назад
debian логотип
CVE-2026-91992

Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...

CVSS3: 5.9
0%
Низкий
5 дней назад
github логотип
GHSA-jqv5-7x9v-7j83

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

CVSS3: 5.9
0%
Низкий
5 дней назад

Уязвимостей на страницу