Safety vulnerability ID: 26161
The information on this page was manually curated by our Cybersecurity Intelligence Team.
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.
Latest version: 6.4.2
Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application