CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.
Loading...
Loading...
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.
May 23, 2012
April 29, 2026
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| tornado | 0.2 ... 2.2 (10 versions) | 2.2.1 | — |
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-2374
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.