← All CVEs NewScan detects
medium

CVE-2026-91992

Tornado CurlAsyncHTTPClient credential reuse (version advisory)

Severity
medium
Affected product
tornado
Affected versions
tornado ≤ 6.5.6
Fixed in
tornado 6.5.7
Added to NewScan
2026-09-18
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints tornado from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-18. Version source: tornado==X.Y.Z pins in requirements.txt, parsed by mine_versions and joined by its pack-derived alias map. Source: https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f (all releases through 6.5.6; fixed 6.5.7). Uses the maintainer's Moderate severity rather than the triage's higher score. CVE association is from the saved NVD triage. Dependency-version advisory only: CurlAsyncHTTPClient/pycurl use, credential-bearing requests and handle reuse are not established by a version pin; no credential disclosure is reproduced.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →