Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop. | |
| Title | Tornado before 6.5.9 Denial of Service via Query String | |
| First Time appeared |
Tornadoweb
Tornadoweb tornado |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tornadoweb
Tornadoweb tornado |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T10:42:04.230Z
Reserved: 2026-09-30T10:55:39.869Z
Link: CVE-2026-103261
No data.
Status : Deferred
Published: 2026-10-01T11:17:20.847
Modified: 2026-10-01T11:17:20.997
Link: CVE-2026-103261
No data.
OpenCVE Enrichment
No data.
Weaknesses