CVE-2026-91992
Tornado CurlAsyncHTTPClient credential reuse (version advisory)
- Severity
- medium
- Affected product
- tornado
- Affected versions
- tornado ≤ 6.5.6
- Fixed in
- tornado 6.5.7
- Added to NewScan
- 2026-09-18
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints tornado from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-18. Version source: tornado==X.Y.Z pins in requirements.txt, parsed by mine_versions and joined by its pack-derived alias map. Source: https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f (all releases through 6.5.6; fixed 6.5.7). Uses the maintainer's Moderate severity rather than the triage's higher score. CVE association is from the saved NVD triage. Dependency-version advisory only: CurlAsyncHTTPClient/pycurl use, credential-bearing requests and handle reuse are not established by a version pin; no credential disclosure is reproduced.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →