Unbounded Memory Accumulation Vulnerability in Tornado Web Framework
CVE-2026-103262

8.7HIGH

Key Information:

Vendor

Tornadoweb

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103262?

The Tornado Web Framework has a vulnerability in versions prior to 6.5.9 that allows remote attackers to exploit unbounded memory accumulation through the CurlAsyncHTTPClient. By sending a specially crafted gzip-encoded response, attackers can create a decompression bomb that fills memory without limits, potentially leading to denial of service as the application becomes unresponsive due to out-of-memory errors.

Affected Version(s)

tornado 0 < 6.5.9

tornado 6.5.9

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iaohkut-from-NightWolf-Team
aoto-tech
.