Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-103261

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Oct 01, 2026
Vendor unknown

Description

Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop.

References