Operation on a Resource after Expiration or Release in Tornado - CVE-2026-91992
Published: September 15, 2026 / Updated: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to failure to clear sensitive state in CurlAsyncHTTPClient when reusing pycurl handles for requests with differing per-request options. A remote attacker can cause a subsequent request to be directed to an attacker-controlled host or proxy to disclose sensitive information.
Exploitation depends on a shared client reusing a handle after requests use different client certificate or proxy credential settings.