Medium severity5.3NVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026
CVE-2026-103261
CVE-2026-103261
Description
Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.5.9
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.