In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade tornado
to version 6.3.3 or higher.
tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.
Affected versions of this package are vulnerable to HTTP Request Smuggling via the parse
and validate strings
capabilities in the int
constructor.
Notes:
haproxy
, although the current release is not affected.