Tornado 6.5.9 之前的版本未能在 中限制查询字符串字段的数量,使得远程攻击者可以通过发送包含数千个查询参数的请求来导致事件循环(event loop)停滞。攻击者可发送未经身份验证的 GET 请求,其中查询字符串字段数量不受限制,从而降低所有共享同一 IOLoop 的客户端的响应时间。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tornadoweb | tornado | 0 ~ 6.5.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103262 | 7.5 HIGH | Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient |
| CVE-2026-103263 | 5.9 MEDIUM | Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink |
No comments yet