Loading market data...
← Back to CVE feed

CVE-2026-103262

HIGH CVSS 7.5 View on NVD ↗

Description

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: Oct 01, 2026 11:17 UTC Modified: Oct 01, 2026 11:17 UTC