chiprook
← Security
SecurityOctober 1, 2026, 12:31

GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient

A high-severity uncontrolled resource consumption flaw (CVSS 7.5) was found in Tornado's libcurl-based CurlAsyncHTTPClient. With response decompression enabled, highly compressed responses cause unbounded memory growth, leading to host memory exhaustion and denial of service. Fixed in Tornado 6.5.9 and 6.6.0.

GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient
#Tornado
Read next
Security

Microsoft: JadePuffer hijacked Azure identities to destroy cloud resources

Security

61% of production cloud resources had no backups, Eon finds

Security

JADEPUFFER attackers used compromised service principals to delete Azure resources

Science

Lockheed Martin rolls out first F-35A stealth jet for Germany to replace aging Tornados