CVE-2023-54397
Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54397.json, https://github.com/tornadoweb/tornado/security/advisories/GHSA-qppv-j76h-2rpx, https://nvd.nist.gov/vuln/detail/CVE-2023-54397, https://www.vulncheck.com/advisories/tornado-before-6.3.3-http-request-smuggling-via-content-length