PT-2026-49119 · Tornado · Tornado

CVE-2026-49855

·

Published

2026-06-13

·

Updated

2026-07-27

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.5.6
Description Gzip decompression routines process data in limited-size chunks but lack an overall limit for the total size of accumulated decompressed chunks. This allows a malicious server to consume unlimited memory when accessed via 'SimpleAsyncHTTPClient' in its default configuration. While 'HTTPServer' is not affected by default, it becomes vulnerable if decompress request=True is set.
Recommendations Update to version 6.5.6 or later. As a temporary workaround, set decompress response=False or use 'CurlAsyncHTTPClient'.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49855
ECHO-7775-EB27-2601
GHSA-MGF9-4VPG-HJ56
OESA-2026-2727
OESA-2026-2728
OPENSUSE-SU-2026:11027-1
OPENSUSE-SU-2026:21067-1
PYSEC-2026-3389
SUSE-SU-2026:22286-1
SUSE-SU-2026:22373-1
SUSE-SU-2026:22430-1
SUSE-SU-2026:22445-1
SUSE-SU-2026:2725-1
SUSE-SU-2026:2726-1
SUSE-SU-2026:3291-1

Affected Products

Tornado