Description
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service; EPSS ~0.4%; not listed in KEV
Action: Apply Patch
AI Analysis

Impact

Tornado before version 6.5.8 contains a memory amplification flaw in the parse_multipart_form_data routine. The routine splits multipart request bodies before checking the configured maximum number of parts, letting an attacker send a large number of parts that creates large transient lists. The resulting memory exhaustion leads to application slowdown or outright failure, causing denial of service.

Affected Systems

The affected software is Tornado, released by tornadoweb. Any installation running a version older than 6.5.8 is vulnerable, as the vulnerability exists up to but not in 6.5.8.

Risk and Exploitability

The CVSS score of 8.7 signals a high‑severity flaw. The EPSS score indicates a very low but non‑zero exploitation probability of about 0.4%, falling within the <1% range, and the vulnerability is not yet listed in the CISA KEV catalog. The flaw can be exploited by any network actor able to send multipart HTTP requests to the Tornado application, making the attack vector likely accessible from external or internal networks that reach the application. Once triggered, memory exhaustion can silently degrade service or drop connections, making it a realistic denial‑of‑service risk in unprotected environments.

Generated by OpenCVE AI on September 20, 2026 at 16:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Tornado to version 6.5.8 or newer, which implements proper max_parts validation before splitting the multipart body.
  • If an upgrade cannot be performed immediately, enforce request size limits or rate limit multipart traffic at the load balancer or reverse proxy to prevent large multipart bodies from reaching the application.
  • Monitor memory usage of the Tornado process and configure alerts for sudden spikes that could indicate mass multipart request attempts.

Generated by OpenCVE AI on September 20, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.
Title Tornado before 6.5.8 Memory Amplification DoS via multipart
First Time appeared Tornadoweb
Tornadoweb tornado
Weaknesses CWE-770
CPEs cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Vendors & Products Tornadoweb
Tornadoweb tornado
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tornadoweb Tornado
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T16:05:11.528Z

Reserved: 2026-09-15T11:11:13.311Z

Link: CVE-2026-91990

cve-icon Vulnrichment

Updated: 2026-09-15T16:05:08.520Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:58.147

Modified: 2026-09-16T13:42:49.167

Link: CVE-2026-91990

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T15:18:31Z

Links: CVE-2026-91990 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling