{"id":"CVE-2026-103262","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-103262","summary":"Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed…","details":"Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.","published":"2026-10-01T11:17:21.050","modified":"2026-10-01T11:17:21.177","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/tornadoweb/tornado/commit/e412435febba4569c552c5c9054f1bf92bd171a9","label":"tornadoweb/tornado@e412435"},"references":[{"type":"WEB","url":"https://github.com/tornadoweb/tornado/commit/e412435febba4569c552c5c9054f1bf92bd171a9"},{"type":"WEB","url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-chx6-46f5-w4vp"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/tornado-before-6.5.9-denial-of-service-via-curlasynchttpclient"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-01T11:17:21.177"}}