{"id":"CVE-2026-91992","title":"Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing","summary":"Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-200","CWE-524"],"vendor":"tornadoweb","product":"tornado","affected":["tornado < 6.5.7"],"patched":["tornado 6.5.7"],"published":"2026-09-15","updated":"2026-09-17","sourceUpdated":"2026-09-17T16:18:32.510","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91992","references":[{"url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/tornado-before-6.5.7-credential-leak-via-handle-reuse","label":"disclosure@vulncheck.com"},{"url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/tornadoweb/tornado"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91992.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-91992"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2533894"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-91992"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91992"}],"tags":["nvd","cve.org","exploit-available","osv","pip","csaf","vex","red-hat"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-17T15:16:04.330169Z"},"epss":0.00206,"epssPercentile":0.10957,"aliases":["GHSA-pw6j-qg29-8w7f"],"ecosystem":"pip","ingestedAt":"2026-09-15T15:39:12.907Z","slug":"CVE-2026-91992","body":"## Overview\n\nTornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-91992)\n\nAffected packages:\n\n- `tornado < 6.5.7`\n\nPatched in:\n\n- `tornado 6.5.7`\n\nSource: https://osv.dev/vulnerability/GHSA-pw6j-qg29-8w7f\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, … · no fix planned: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91992.json)","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":32.5,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":206254,"id":"CVE-2026-91992","ts":1789662143500,"field":"exploit_available","old":"false","new":"true"}]}