Unbounded Memory Accumulation Vulnerability in Tornado Web Framework
CVE-2026-103262
8.7HIGH
What is CVE-2026-103262?
The Tornado Web Framework has a vulnerability in versions prior to 6.5.9 that allows remote attackers to exploit unbounded memory accumulation through the CurlAsyncHTTPClient. By sending a specially crafted gzip-encoded response, attackers can create a decompression bomb that fills memory without limits, potentially leading to denial of service as the application becomes unresponsive due to out-of-memory errors.
Affected Version(s)
tornado 0 < 6.5.9
tornado 6.5.9
