Denial of Service Flaw in Tornado Web Framework by Tornado Software
CVE-2026-103261
6.9MEDIUM
What is CVE-2026-103261?
Tornado, a popular web framework, prior to version 6.5.9 is vulnerable to a Denial of Service condition. The issue arises from the failure to limit the number of query string fields in the HTTPServerRequest.init method. This allows remote attackers to exploit the server by sending GET requests with an unbounded number of query parameters. Such misuse can lead to event-loop stalling, significantly degrading the response times for all users sharing the same IOLoop. To protect your applications, it is essential to update to the latest version or implement mitigating measures as detailed in the vendor’s advisory.
Affected Version(s)
tornado 0 < 6.5.9
tornado 6.5.9
