{"id":"CVE-2024-58384","title":"Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers","summary":"Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitr…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-113","CWE-93"],"vendor":"tornadoweb","product":"tornado","affected":["tornado < 6.4.1"],"patched":["tornado 6.4.1"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T20:16:48.880","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-58384","references":[{"url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-w235-7p84-xx57","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tornado-before-6.4.1-crlf-injection-via-curlasynchttpclient","label":"disclosure@vulncheck.com"},{"url":"https://github.com/tornadoweb/tornado/commit/7786f09f84c9f3f2012c4cf3878417cb9f053669"},{"url":"https://github.com/tornadoweb/tornado"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-58384.json"},{"url":"https://access.redhat.com/security/cve/CVE-2024-58384"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533897"},{"url":"https://www.cve.org/CVERecord?id=CVE-2024-58384"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-58384"}],"tags":["nvd","cve.org","osv","pip","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T19:16:19.322432Z"},"epss":0.00242,"epssPercentile":0.15684,"aliases":["GHSA-w235-7p84-xx57"],"ecosystem":"pip","scores":{"nvd":5.4,"osv":6.5,"vendor":5.4},"ingestedAt":"2026-09-15T15:39:12.929Z","slug":"CVE-2024-58384","body":"## Overview\n\nTornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2024-58384)\n\nAffected packages:\n\n- `tornado < 6.4.1`\n\nPatched in:\n\n- `tornado 6.4.1`\n\nSource: https://osv.dev/vulnerability/GHSA-w235-7p84-xx57\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, … · no fix planned: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-58384.json)","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}