PT-2026-24805 · Tornado+4 · Tornado+4

0X-Apollyon

+1

·

Published

2026-03-11

·

Updated

2026-06-08

·

CVE-2026-31958

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.5.5
Description Tornado is a Python web framework and asynchronous networking library. In versions prior to 6.5.5, the only limit on the number of parts in multipart/form-data requests is the max body size setting, which defaults to 100MB. Because parsing of these requests occurs synchronously on the main thread, this can lead to a denial-of-service condition due to the computational cost of processing very large multipart bodies with numerous parts. Tornado 6.5.5 introduces new limits on the size and complexity of multipart bodies, including a default limit of 100 parts per request, configurable through tornado.httputil.ParseMultipartConfig. It is also possible to disable multipart/form-data parsing entirely if it is not required.
Recommendations Versions prior to 6.5.5 should be updated to version 6.5.5 or later.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2026:13641
ALSA-2026:13670
ALSA-2026:19034
ALSA-2026:19189
ALSA-2026:8093
BDU:2026-07190
CLEANSTART-2026-AN27706
CVE-2026-31958
ECHO-5939-F806-1836
GHSA-QJXF-F2MG-C6MC
OESA-2026-1673
OESA-2026-1674
OESA-2026-1675
OESA-2026-1676
OESA-2026-1677
OESA-2026-1995
OPENSUSE-SU-2026:10374-1
OPENSUSE-SU-2026:10389-1
OPENSUSE-SU-2026:20406-1
OPENSUSE-SU-2026:20918-1
PYSEC-2026-140
RHSA-2026:11454
RHSA-2026:11493
RHSA-2026:11494
RHSA-2026:11495
RHSA-2026:13641
RHSA-2026:13670
RHSA-2026:19034
RHSA-2026:19189
RHSA-2026:20572
RHSA-2026:20573
RHSA-2026:20577
RHSA-2026:20810
RHSA-2026:8093
SUSE-SU-2026:1064-1
SUSE-SU-2026:1162-1
SUSE-SU-2026:1171-1
SUSE-SU-2026:1519-1
SUSE-SU-2026:1520-1
SUSE-SU-2026:1521-1
SUSE-SU-2026:1523-1
SUSE-SU-2026:1525-1
SUSE-SU-2026:20761-1
SUSE-SU-2026:20770-1
SUSE-SU-2026:20797-1
SUSE-SU-2026:20919-1
SUSE-SU-2026:21990-1
SUSE-SU-2026:21993-1
SUSE-SU-2026:2242-1
SUSE-SU-2026:2244-1
SUSE-SU-2026:2252-1
SUSE-SU-2026:2255-1
SUSE-SU-2026:2256-1
SUSE-SU-2026:2257-1
SUSE-SU-2026:2265-1
USN-8198-1
USN-8198-2

Affected Products

Linuxmint
Red Os
Rocky Linux
Tornado
Ubuntu