{"id":"CVE-2023-54397","aliases":["GHSA-qppv-j76h-2rpx"],"url":"https://o3.security/vulnerability/CVE-2023-54397","summary":"Tornado before 6.3.3 HTTP Request Smuggling via Content-Length","details":"Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.","published":"2026-09-15T15:17:52.261Z","modified":"2026-09-16T03:45:36.474185632Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"tornado","fixedVersion":"6.3.3"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/54xxx/CVE-2023-54397.json"},{"type":"ADVISORY","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-qppv-j76h-2rpx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-54397"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/tornado-before-6.3.3-http-request-smuggling-via-content-length"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:45:36.474185632Z"}}