{"id":"AZL-103101","summary":"CVE-2024-14029 affecting package python-tornado 6.3.3-11","details":"Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.","modified":"2026-09-21T05:37:51Z","published":"2026-09-15T16:17:06Z","upstream":["CVE-2024-14029"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-14029"}],"affected":[{"package":{"name":"python-tornado","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-tornado"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.3.3-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103101.json"}}],"schema_version":"1.9.0"}