Impact
Tornado versions earlier than 6.5.9 contain an unbounded memory accumulation flaw in the CurlAsyncHTTPClient component. The client decompresses gzip‑encoded responses without enforcing any size limit. A malicious server can therefore send a decompression bomb that grows the client’s memory usage until the process runs out of memory and crashes. This flaw is classified as an improper limit or range validation weakness (CWE‑409) and results in a loss of availability for the affected service.
Affected Systems
The vulnerability affects any deployment of Tornado that employs the CurlAsyncHTTPClient component and is running a release prior to 6.5.9. This includes all builds derived from source or distributed as binaries, regardless of the host operating system or network exposure.
Risk and Exploitability
The flaw is rated high with a CVSS score of 8.7. Although the EPSS score is not available and the issue is not listed in CISA’s KEV catalog, the attack path is straightforward: a remote attacker sends a crafted HTTP response that contains a gzip‑encoded decompression bomb. No authentication or special privileges are required. The resulting out‑of‑memory condition can be triggered with a single request, making the vulnerability attractive for attackers seeking to disrupt service availability.
OpenCVE Enrichment