High severity7.5GHSA Advisory· Published Jul 14, 2026· Updated Jul 16, 2026
CVE-2026-49855
CVE-2026-49855
Description
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tornadoPyPI | < 6.5.6 | 6.5.6 |
Affected products
6- Range: < 6.5.6
- osv-coords5 versionspkg:apk/chainguard/mitmproxypkg:apk/wolfi/mitmproxypkg:pypi/tornadopkg:rpm/opensuse/python-tornado6&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-tornado6&distro=openSUSE%20Tumbleweed
< 12.2.3-r1+ 4 more
- (no CPE)range: < 12.2.3-r1
- (no CPE)range: < 12.2.3-r1
- (no CPE)range: < 6.5.6
- (no CPE)range: < 6.5-160000.5.1
- (no CPE)range: < 6.5.7-1.1
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.