Description
Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.
Published: 2026-10-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Tornado versions earlier than 6.5.9 contain an unbounded memory accumulation flaw in the CurlAsyncHTTPClient component. The client decompresses gzip‑encoded responses without enforcing any size limit. A malicious server can therefore send a decompression bomb that grows the client’s memory usage until the process runs out of memory and crashes. This flaw is classified as an improper limit or range validation weakness (CWE‑409) and results in a loss of availability for the affected service.

Affected Systems

The vulnerability affects any deployment of Tornado that employs the CurlAsyncHTTPClient component and is running a release prior to 6.5.9. This includes all builds derived from source or distributed as binaries, regardless of the host operating system or network exposure.

Risk and Exploitability

The flaw is rated high with a CVSS score of 8.7. Although the EPSS score is not available and the issue is not listed in CISA’s KEV catalog, the attack path is straightforward: a remote attacker sends a crafted HTTP response that contains a gzip‑encoded decompression bomb. No authentication or special privileges are required. The resulting out‑of‑memory condition can be triggered with a single request, making the vulnerability attractive for attackers seeking to disrupt service availability.

Generated by OpenCVE AI on October 1, 2026 at 14:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Tornado to version 6.5.9 or later to eliminate the flaw.
  • If upgrading is not immediately possible, configure the application to avoid using CurlAsyncHTTPClient for untrusted external traffic or replace it with an HTTP client that imposes a decompression size limit.
  • Apply system‑level resource limits, such as cgroups or ulimit, or position a reverse proxy to cap memory usage and prevent the process from being terminated by an out‑of‑memory condition.

Generated by OpenCVE AI on October 1, 2026 at 14:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.
Title Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient
First Time appeared Tornadoweb
Tornadoweb tornado
Weaknesses CWE-409
CPEs cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Vendors & Products Tornadoweb
Tornadoweb tornado
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tornadoweb Tornado
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T10:42:04.913Z

Reserved: 2026-09-30T10:55:39.869Z

Link: CVE-2026-103262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T11:17:21.050

Modified: 2026-10-01T11:17:21.177

Link: CVE-2026-103262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:00:12Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)