Bug 2500686 (CVE-2026-49855) - CVE-2026-49855 tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption
Summary: CVE-2026-49855 tornado: Tornado: Denial of Service via uncontrolled gzip deco...
Keywords:
Status: NEW
Alias: CVE-2026-49855
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2522080 2522081 2522082
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-14 21:05 UTC by OSIDB Bzimport
Modified: 2026-09-01 13:31 UTC (History)
49 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-14 21:05:08 UTC
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.


Note You need to log in before you can comment on or make changes to this bug.