Denial of Service Flaw in Tornado Web Framework by Tornado Software
CVE-2026-103261

6.9MEDIUM

Key Information:

Vendor

Tornadoweb

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103261?

Tornado, a popular web framework, prior to version 6.5.9 is vulnerable to a Denial of Service condition. The issue arises from the failure to limit the number of query string fields in the HTTPServerRequest.init method. This allows remote attackers to exploit the server by sending GET requests with an unbounded number of query parameters. Such misuse can lead to event-loop stalling, significantly degrading the response times for all users sharing the same IOLoop. To protect your applications, it is essential to update to the latest version or implement mitigating measures as detailed in the vendor’s advisory.

Affected Version(s)

tornado 0 < 6.5.9

tornado 6.5.9

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iaohkut-from-NightWolf-Team
manus-pi
.