Summary
CVE-2024-14029 is an HTTP request smuggling vulnerability in the Tornado Python web framework (TornadoServer), affecting all versions prior to 6.4.1. Tornado’s HTTP server ignores duplicate Transfer-Encoding: chunked headers, causing it to misinterpret a request’s message body boundaries. When Tornado is deployed behind a reverse proxy or load balancer, this parsing inconsistency can be abused to smuggle a second, attacker-controlled request, enabling access control bypass, cache poisoning, or connection desynchronization. The issue is rated CRITICAL (CVSS v4.0 base score 9.0).
Technical details
- Root cause: Tornado’s HTTP request parser ignores a duplicated
Transfer-Encoding: chunkedheader on an incoming request, treating the request as having no message body. - Trigger conditions: A crafted request containing more than one
Transfer-Encoding: chunkedheader is sent to a Tornado server. Tornado then parses the "bodiless" request’s remaining chunked data as the start of a separate, subsequent request. - Attack vector: Network-based (AV:N); exploitation requires Tornado to be running behind a front-end proxy, load balancer, or CDN that interprets the duplicated header differently, creating the classic request-smuggling desynchronization between front-end and back-end.
- Impact: Desynchronized connections between proxy and Tornado backend can allow attackers to bypass access controls enforced at the proxy layer, poison shared caches, or hijack/inject requests belonging to other users.
- Classification: CWE-444 — Inconsistent Interpretation of HTTP Requests ("HTTP Request/Response Smuggling").
Affected software
- Tornado (PyPI package
tornado) versions prior to 6.4.1 - Fixed in Tornado 6.4.1 and later
Severity
- CVSS v4.0: 9.0 (Critical) —
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N - CVSS v3.1: 7.5 (High) —
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Mitigation and recommended actions
- Immediate: Upgrade Tornado to version 6.4.1 or later, which correctly rejects/handles requests containing duplicate
Transfer-Encodingheaders. - If patching is not immediately possible:
- Configure any front-end proxy, load balancer, or CDN placed in front of Tornado to normalize or reject requests containing duplicate
Transfer-Encodingheaders before forwarding them. - Ensure the proxy and Tornado backend agree on HTTP/1.1 message-framing rules (Transfer-Encoding vs. Content-Length) to eliminate smuggling opportunities.
- Monitor and restrict direct network exposure of Tornado instances that sit behind proxies to reduce the risk of desynchronization attacks while patching is scheduled.
- Configure any front-end proxy, load balancer, or CDN placed in front of Tornado to normalize or reject requests containing duplicate

