CVE-2026-103262 UNKNOWN

CVE-2026-103262

Published: 2026-10-01

Description

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…