CVE-2026-103261

MEDIUM Status: Deferred

CVSS Scores

CVSS v3.x Base Score
5.3
MEDIUM

Description

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop.

Published
October 1, 2026 11:17 AM
Last Modified
October 1, 2026 11:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-770

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.