GHSA-3HV7-MJH2-FV65: Unbounded Query-String Parsing Denial of Service in Tornado Web Server
Vulnerability ID: GHSA-3HV7-MJH2-FV65
CVSS Score: 5.3
Published: 2026-09-30
An uncontrolled resource consumption vulnerability in Tornado's HTTP query-string parser allows remote, unauthenticated attackers to trigger CPU exhaustion and block the single-threaded event loop via crafted request URIs containing large numbers of parameters.
TL;DR
A design asymmetry in Tornado's query-string parser allows unbounded key-value field processing on GET requests, allowing remote attackers to starve CPU resources and block the event loop, causing a denial of service.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-400 (Uncontrolled Resource Consumption) / CWE-407 (Algorithmic Complexity)
- Attack Vector: Network (Unauthenticated)
- CVSS v3.1 Score: 5.3 (Medium)
- EPSS Score: Not Applicable (requires CVE ID)
- Exploit Status: PoC (Proof-of-Concept)
- CISA KEV Status: Not Applicable
- Impact: Denial of Service (DoS)
Affected Systems
- Tornado Web Server
-
tornado: < 6.5.9 (Fixed in:
6.5.9)
Code Analysis
Commit: 0394513
httputil: Apply the argument count limit to query strings
Commit: 8a61dd6
Branch 6.5 cherry-pick: Apply the argument count limit to query strings
Exploit Details
- GitHub Security Advisory GHSA-3hv7-mjh2-fv65: Official advisory with detailed reproduction specifications and timeline.
Mitigation Strategies
- Upgrade Tornado package to version 6.5.9 or higher.
- Configure front-end reverse proxies (Nginx/HAProxy) to drop requests with query strings longer than 8KB.
- Enforce tighter global 'max_header_size' configurations in Tornado startup initialization.
Remediation Steps:
- Locate the requirements or dependency files (e.g., requirements.txt, pyproject.toml) of the affected project.
- Update the tornado version to 'tornado>=6.5.9'.
- Run the package manager installation command, such as 'pip install -U tornado'.
- Validate the fix by attempting to send a GET query string containing more than 1,000 arguments and verifying that the server responds with an HTTP 400 Bad Request.
References
- GitHub Security Advisory GHSA-3hv7-mjh2-fv65
- Tornado Fix Pull Request #3719
- Tornado v6.5.9 Release Tag
- Tornado Repository
Read the full report for GHSA-3HV7-MJH2-FV65 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)