<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:57:43 +0000</lastBuildDate>
    <item>
      <title>BREW-jupyterlab-GHSA-qppv-j76h-2rpx — Tornado vulnerable to HTTP request smuggling via improper parsing of `Content-Length` fields and chunk lengths</title>
      <link>https://cve.radiocsirt.org/vuln/brew-jupyterlab-ghsa-qppv-j76h-2rpx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;## Summary
Tornado interprets `-`, `+`, and `_` in chunk length and `Content-Length` values, which are not allowed by the HTTP RFCs. This can result in request smuggling when Tornado is deployed behind certain proxies that interpret those non-standard characters differently. This is known to apply to older versions of haproxy, although the current release is not affected.&lt;/p&gt;
&lt;p&gt;## Details
Tornado uses the `int` constructor to parse the values of `Content-Length` headers and chunk lengths in the following locations:
### `tornado/http1connection.py:445`
```python3
            self._expected_content_remaining = int(headers[&amp;#34;Content-Length&amp;#34;])
```
### `tornado/http1connection.py:621`
```python3
                content_length = int(headers[&amp;#34;Content-Length&amp;#34;])  # type: Optional[int]
```
### `tornado/http1connection.py:671`
```python3
            chunk_len = int(chunk_len_str.strip(), 16)
```
Because `int(&amp;#34;0_0&amp;#34;) == int(&amp;#34;+0&amp;#34;) == int(&amp;#34;-0&amp;#34;) == int(&amp;#34;0&amp;#34;)`, using the `int` constructor to parse and validate strings that should contain only ASCII digits is not a good strategy.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;## Summary
Tornado interprets `-`, `+`, and `_` in chunk length and `Content-Length` values, which are not allowed by the HTTP RFCs. This can result in request smuggling when Tornado is deployed behind certain proxies that interpret those non-standard characters differently. This is known to apply to older versions of haproxy, although the current release is not affected.&lt;/p&gt;
&lt;p&gt;## Details
Tornado uses the `int` constructor to parse the values of `Content-Length` headers and chunk lengths in the following locations:
### `tornado/http1connection.py:445`
```python3
            self._expected_content_remaining = int(headers[&amp;#34;Content-Length&amp;#34;])
```
### `tornado/http1connection.py:621`
```python3
                content_length = int(headers[&amp;#34;Content-Length&amp;#34;])  # type: Optional[int]
```
### `tornado/http1connection.py:671`
```python3
            chunk_len = int(chunk_len_str.strip(), 16)
```
Because `int(&amp;#34;0_0&amp;#34;) == int(&amp;#34;+0&amp;#34;) == int(&amp;#34;-0&amp;#34;) == int(&amp;#34;0&amp;#34;)`, using the `int` constructor to parse and validate strings that should contain only ASCII digits is not a good strategy.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-jupyterlab-ghsa-qppv-j76h-2rpx</guid>
    </item>
    <item>
      <title>EUVD-2026-370567</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-370567</link>
      <description>EUVD-2026-370567</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-370567</guid>
    </item>
    <item>
      <title>fkie_cve-2023-54397</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-54397</link>
      <description>&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-54397</guid>
    </item>
    <item>
      <title>GHSA-rhr2-ccgv-xvgx</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rhr2-ccgv-xvgx</link>
      <description>&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rhr2-ccgv-xvgx</guid>
    </item>
    <item>
      <title>OESA-2026-4034 — python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4034</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed. By using non-blocking network I/O, Tornado can scale to tens of thousands of open connections, making it ideal for long polling, WebSockets, and other applications that require a long-lived connection to each user.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.(CVE-2023-54397)&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.(CVE-2024-14029)&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.(CVE-2024-58384)&lt;/p&gt;
&lt;p&gt;Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validatin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed. By using non-blocking network I/O, Tornado can scale to tens of thousands of open connections, making it ideal for long polling, WebSockets, and other applications that require a long-lived connection to each user.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.(CVE-2023-54397)&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.(CVE-2024-14029)&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.(CVE-2024-58384)&lt;/p&gt;
&lt;p&gt;Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validatin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4034</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2023-54397</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-54397</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2023-54397</guid>
    </item>
  </channel>
</rss>
