Tornado 6.5.9 之前的版本在 CurlAsyncHTTPClient 中存在一个无界内存累积漏洞,允许远程攻击者通过发送压缩响应来触发拒绝服务(DoS)攻击。攻击者可发送一个经过 gzip 编码的“解压炸弹”,该数据在内存中无限制地累积,最终导致应用程序进程因内存耗尽(OOM)而被终止。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tornadoweb | tornado | 0 ~ 6.5.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103263 | 5.9 MEDIUM | Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink |
| CVE-2026-103261 | 5.3 MEDIUM | Tornado before 6.5.9 Denial of Service via Query String |
No comments yet