๐Ÿ” CVE Alert

CVE-2026-103262

HIGH 7.5

Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.

CWE CWE-409
Vendor tornadoweb
Product tornado
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for tornadoweb tornado

Be the first to know when new high vulnerabilities affecting tornadoweb tornado are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

tornadoweb / tornado
0 < 6.5.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tornadoweb/tornado/security/advisories/GHSA-chx6-46f5-w4vp github.com: https://github.com/tornadoweb/tornado/commit/e412435febba4569c552c5c9054f1bf92bd171a9 vulncheck.com: https://www.vulncheck.com/advisories/tornado-before-6.5.9-denial-of-service-via-curlasynchttpclient

Credits

๐Ÿ” iaohkut-from-NightWolf-Team ๐Ÿ” aoto-tech