Loading
Generated remediation guidance and an executive summary. No account required.
CRLF injection vulnerability in the tornado.web.RequestHandler.set_header function in Tornado before 2.2.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input.
Cite this page
CVE-2012-2374. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2012-2374
Use CWE-20, Tornadoweb vendor hub and Tornado product page to widen CVE-2012-2374 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-31958, CVE-2025-67726 and CVE-2025-67725 for nearby disclosures in the same product family.