Impact
Tornado versions earlier than 6.5.9 do not restrict the number of query string fields accepted in the HTTPServerRequest.__init__ method, allowing an attacker to send HTTP GET requests containing thousands of query parameters. This unbounded input can cause the event loop to stall, severely degrading response times for all clients that share the same IOLoop. The vulnerability is classified as CWE-770 (Uncontrolled Resource Consumption).
Affected Systems
All installations of Tornado under the vendor tornadoweb that use a version prior to 6.5.9 are affected. The vulnerability applies to any deployment that processes HTTP requests using the Tornado HTTPServerRequest component without additional request filtering.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity for this Denial of Service. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting the exploitation probability is uncertain but non-negligible. Attackers can exploit the weakness remotely by sending unauthenticated GET requests with an unbounded number of query parameters over the network. The lack of authentication and the ability to affect all clients on the shared IOLoop mean that a successful attack could diminish service availability for multiple users.
OpenCVE Enrichment