CVE-2026-103262
Deferred Deferred - Pending Action

Memory Exhaustion in Tornado via Gzip Decompression Bomb

Vulnerability report for CVE-2026-103262, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tornadoweb tornado to 6.5.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-409 The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Tornado versions before 6.5.9 in the CurlAsyncHTTPClient component. It allows remote attackers to cause denial of service by sending a compressed response that triggers unbounded memory accumulation. Specifically, attackers can send a gzip-encoded decompression bomb, which expands into large amounts of data in memory without size limits, eventually killing the application process due to out-of-memory conditions.

Detection Guidance

To detect this vulnerability, monitor for applications using Tornado versions before 6.5.9 with CurlAsyncHTTPClient. Check for unusually high memory usage in Tornado-based applications when processing HTTP responses. Inspect network traffic for gzip-compressed responses from untrusted sources. Use commands like 'ps aux | grep tornado' to identify running Tornado processes and 'curl -I http://target' to check server responses for compression headers.

  • Check Tornado version: python -c "import tornado; print(tornado.version)"
  • Monitor memory usage: top -p $(pgrep -f tornado) or htop for Tornado processes
  • Inspect HTTP responses: curl -v --compressed http://example.com to test compression handling
Impact Analysis

If you use a vulnerable Tornado version (before 6.5.9) with CurlAsyncHTTPClient enabled, an attacker could send a malicious response to your application, causing it to consume excessive memory. This may lead to the application crashing or becoming unresponsive, resulting in downtime for services relying on Tornado. The attack requires no special privileges or user interaction, only that your application fetches a URL controlled by the attacker.

Mitigation Strategies

Immediately upgrade Tornado to version 6.5.9 or later. If upgrading is not possible, disable CurlAsyncHTTPClient by setting 'decompress_response=False' in CurlAsyncHTTPClient instances. Implement network-level protections like WAF rules to block gzip-compressed responses from untrusted sources. Set 'max_body_size' to a reasonable limit (e.g., 10MB) in CurlAsyncHTTPClient configurations.

  • Upgrade Tornado: pip install --upgrade tornado>=6.5.9
  • Disable decompression: client = CurlAsyncHTTPClient(decompress_response=False)
  • Configure size limits: client = CurlAsyncHTTPClient(max_body_size=10485760)

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103262. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart