MEDIUM 6.9 NVD
CVE-2026-103261
Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by s
Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop.
References
- https://github.com/tornadoweb/tornado/commit/03945136ea9746eccf61caf88edae39642e59c93
- https://github.com/tornadoweb/tornado/security/advisories/GHSA-3hv7-mjh2-fv65
- https://www.vulncheck.com/advisories/tornado-before-6.5.9-denial-of-service-via-query-stri
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.