Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions. | |
| Title | Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient | |
| First Time appeared |
Tornadoweb
Tornadoweb tornado |
|
| Weaknesses | CWE-409 | |
| CPEs | cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tornadoweb
Tornadoweb tornado |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T10:42:04.913Z
Reserved: 2026-09-30T10:55:39.869Z
Link: CVE-2026-103262
No data.
Status : Deferred
Published: 2026-10-01T11:17:21.050
Modified: 2026-10-01T11:17:21.177
Link: CVE-2026-103262
No data.
OpenCVE Enrichment
No data.
-
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)