GHSA-2v9w-f3h6-74rjMediumCVSS 5.3

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest...

Published
October 1, 2026
Last Modified
October 1, 2026

🔗 CVE IDs covered (1)

📋 Description

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.init, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop.

🔗 References (5)