Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8093 https://access.redhat.com/errata/RHSA-2026:8093
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:11454 https://access.redhat.com/errata/RHSA-2026:11454
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:11494 https://access.redhat.com/errata/RHSA-2026:11494
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:11495 https://access.redhat.com/errata/RHSA-2026:11495
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:11493 https://access.redhat.com/errata/RHSA-2026:11493
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:13641 https://access.redhat.com/errata/RHSA-2026:13641
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:13670 https://access.redhat.com/errata/RHSA-2026:13670