HIGH 8.7 NVD
CVE-2026-91990
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit
Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.
References
- https://github.com/tornadoweb/tornado/security/advisories/GHSA-8423-8fgw-73vq
- https://www.vulncheck.com/advisories/tornado-before-6.5.8-memory-amplification-dos-via-mul
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-15 via NVD.
vulnfeed aggregates 13549 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.