---
id: CVE-2026-91992
title: >-
  Tornado before 6.5.7 contains a credential leak vulnerability in
  CurlAsyncHTTPClient where pycurl handles are reused across requests without
  proper state clearing
summary: >-
  Tornado before 6.5.7 contains a credential leak vulnerability in
  CurlAsyncHTTPClient where pycurl handles are reused across requests without
  proper state clearing. Attackers can obtain sensitive credentials by issuing
  requests through th…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
  - CWE-524
vendor: tornadoweb
product: tornado
affected:
  - tornado < 6.5.7
patched:
  - tornado 6.5.7
published: '2026-09-15'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T16:18:32.510'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91992'
references:
  - url: >-
      https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tornado-before-6.5.7-credential-leak-via-handle-reuse
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/tornadoweb/tornado'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91992.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91992'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533894'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-91992'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91992'
tags:
  - nvd
  - cve.org
  - exploit-available
  - osv
  - pip
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T15:16:04.330169Z'
epss: 0.00262
epssPercentile: 0.15974
aliases:
  - GHSA-pw6j-qg29-8w7f
ecosystem: pip
ingestedAt: '2026-09-15T15:39:12.907Z'
---

## Overview

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS certificates or proxy authentication to persist across unintended requests.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-91992)

Affected packages:

- `tornado < 6.5.7`

Patched in:

- `tornado 6.5.7`

Source: https://osv.dev/vulnerability/GHSA-pw6j-qg29-8w7f

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Lightspeed Core, Migration Toolkit for Applications 8, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux 10, … · no fix planned: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91992.json)
