CVE-2026-103262
EUVD-2026-9065601.10.2026, 11:17
Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| tornadoweb | tornado | 𝑥 < 6.5.9 | CNA |
Debian Releases
Common Weakness Enumeration