CVE-2026-103261

Summary

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.init, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop.

Affected Software

VendorProductVersion RangeStatus
tornadowebtornado0 < 6.5.9affected
tornadowebtornado6.5.9unaffected

Weaknesses

  • CWE-770: Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References