Vulnerability Database

309,364

Total vulnerabilities in the database

CVE-2012-2374

CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.

  • Published: May 23, 2012
  • Updated: Nov 9, 2025
  • CVE: CVE-2012-2374
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N

CWEs: