GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient
A high-severity uncontrolled resource consumption flaw (CVSS 7.5) was found in Tornado's libcurl-based CurlAsyncHTTPClient. With response decompression enabled, highly compressed responses cause unbounded memory growth, leading to host memory exhaustion and denial of service. Fixed in Tornado 6.5.9 and 6.6.0.
- CVSS 7.5, CWE-409 and CWE-400, network attack vector, unauthenticated
- Affects tornado.curl_httpclient.CurlAsyncHTTPClient in Tornado < 6.5.9
- Fixed in Tornado 6.5.9 and 6.6.0, PoC available
- Workaround: switch to SimpleAsyncHTTPClient or set decompress_response=False
Read next
Security