{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-58384","assignerOrgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","state":"PUBLISHED","assignerShortName":"VulnCheck","dateReserved":"2026-08-16T13:02:14.691Z","datePublished":"2026-09-15T15:17:53.619Z","dateUpdated":"2026-09-17T19:29:06.047Z"},"containers":{"cna":{"providerMetadata":{"orgId":"83251b91-4cc7-4094-a5c7-464a1b83ea10","shortName":"VulnCheck","dateUpdated":"2026-09-15T15:17:53.619Z"},"datePublic":"2024-06-06T00:00:00.000Z","title":"Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient","descriptions":[{"lang":"en","value":"Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests."}],"problemTypes":[{"descriptions":[{"lang":"en","description":"Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')","cweId":"CWE-113","type":"CWE"}]}],"affected":[{"vendor":"tornadoweb","product":"tornado","defaultStatus":"unaffected","packageURL":"pkg:pypi/tornado","versions":[{"version":"0","status":"affected","versionType":"semver","lessThan":"6.4.1"},{"version":"6.4.1","status":"unaffected","versionType":"semver"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*","versionEndExcluding":"6.4.1"}]}]}],"metrics":[{"cvssV4_0":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","subAvailabilityImpact":"NONE","baseScore":6.3,"baseSeverity":"MEDIUM","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","exploitMaturity":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS"},{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","version":"3.1"},"format":"CVSS"}],"references":[{"url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-w235-7p84-xx57","tags":["vendor-advisory"],"name":"GitHub Security Advisory (GHSA-w235-7p84-xx57)"},{"name":"VulnCheck Advisory: Tornado before 6.4.1 CRLF Injection via CurlAsyncHTTPClient","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/tornado-before-6.4.1-crlf-injection-via-curlasynchttpclient"}],"credits":[{"lang":"en","value":"sha0sum","type":"reporter"},{"lang":"en","value":"mschwager","type":"reporter"},{"lang":"en","value":"ahpaleus","type":"reporter"}],"x_generator":{"engine":"vulncheck-endgame"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-09-17T19:16:19.322432Z","id":"CVE-2024-58384","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-17T19:29:06.047Z"}}]}}