CVE-2024-14029: Tornadoweb Tornado
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.
Affected products
- Tornadoweb Tornado: before 6.4.1 (fixed in 6.4.1)
Published 2026-09-15. Last modified 2026-09-28.