---
id: CVE-2024-58384
title: >-
  Tornado before 6.4.1 contains a CRLF injection vulnerability in
  CurlAsyncHTTPClient that fails to reject carriage return and line feed
  characters in request headers
summary: >-
  Tornado before 6.4.1 contains a CRLF injection vulnerability in
  CurlAsyncHTTPClient that fails to reject carriage return and line feed
  characters in request headers. Attackers can inject CRLF sequences into header
  values to inject arbitr…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-113
  - CWE-93
vendor: tornadoweb
product: tornado
affected:
  - tornado < 6.4.1
patched:
  - tornado 6.4.1
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T20:16:48.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58384'
references:
  - url: >-
      https://github.com/tornadoweb/tornado/security/advisories/GHSA-w235-7p84-xx57
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tornado-before-6.4.1-crlf-injection-via-curlasynchttpclient
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/tornadoweb/tornado/commit/7786f09f84c9f3f2012c4cf3878417cb9f053669
  - url: 'https://github.com/tornadoweb/tornado'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-58384.json
  - url: 'https://access.redhat.com/security/cve/CVE-2024-58384'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533897'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-58384'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-58384'
tags:
  - nvd
  - cve.org
  - osv
  - pip
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T19:16:19.322432Z'
epss: 0.00242
epssPercentile: 0.1383
aliases:
  - GHSA-w235-7p84-xx57
ecosystem: pip
scores:
  nvd: 5.4
  osv: 6.5
  vendor: 5.4
ingestedAt: '2026-09-15T15:39:12.929Z'
---

## Overview

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2024-58384)

Affected packages:

- `tornado < 6.4.1`

Patched in:

- `tornado 6.4.1`

Source: https://osv.dev/vulnerability/GHSA-w235-7p84-xx57

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, … · no fix planned: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-58384.json)
