Impact
Tornado before version 6.5.8 contains a memory amplification flaw in the parse_multipart_form_data routine. The routine splits multipart request bodies before checking the configured maximum number of parts, letting an attacker send a large number of parts that creates large transient lists. The resulting memory exhaustion leads to application slowdown or outright failure, causing denial of service.
Affected Systems
The affected software is Tornado, released by tornadoweb. Any installation running a version older than 6.5.8 is vulnerable, as the vulnerability exists up to but not in 6.5.8.
Risk and Exploitability
The CVSS score of 8.7 signals a high‑severity flaw. The EPSS score indicates a very low but non‑zero exploitation probability of about 0.4%, falling within the <1% range, and the vulnerability is not yet listed in the CISA KEV catalog. The flaw can be exploited by any network actor able to send multipart HTTP requests to the Tornado application, making the attack vector likely accessible from external or internal networks that reach the application. Once triggered, memory exhaustion can silently degrade service or drop connections, making it a realistic denial‑of‑service risk in unprotected environments.
OpenCVE Enrichment