DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-3HV7-MJH2-FV65: GHSA-3HV7-MJH2-FV65: Unbounded Query-String Parsing Denial of Service in Tornado Web Server

GHSA-3HV7-MJH2-FV65: Unbounded Query-String Parsing Denial of Service in Tornado Web Server

Vulnerability ID: GHSA-3HV7-MJH2-FV65
CVSS Score: 5.3
Published: 2026-09-30

An uncontrolled resource consumption vulnerability in Tornado's HTTP query-string parser allows remote, unauthenticated attackers to trigger CPU exhaustion and block the single-threaded event loop via crafted request URIs containing large numbers of parameters.

TL;DR

A design asymmetry in Tornado's query-string parser allows unbounded key-value field processing on GET requests, allowing remote attackers to starve CPU resources and block the event loop, causing a denial of service.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-400 (Uncontrolled Resource Consumption) / CWE-407 (Algorithmic Complexity)
  • Attack Vector: Network (Unauthenticated)
  • CVSS v3.1 Score: 5.3 (Medium)
  • EPSS Score: Not Applicable (requires CVE ID)
  • Exploit Status: PoC (Proof-of-Concept)
  • CISA KEV Status: Not Applicable
  • Impact: Denial of Service (DoS)

Affected Systems

  • Tornado Web Server
  • tornado: < 6.5.9 (Fixed in: 6.5.9)

Code Analysis

Commit: 0394513

httputil: Apply the argument count limit to query strings

Commit: 8a61dd6

Branch 6.5 cherry-pick: Apply the argument count limit to query strings

Exploit Details

Mitigation Strategies

  • Upgrade Tornado package to version 6.5.9 or higher.
  • Configure front-end reverse proxies (Nginx/HAProxy) to drop requests with query strings longer than 8KB.
  • Enforce tighter global 'max_header_size' configurations in Tornado startup initialization.

Remediation Steps:

  1. Locate the requirements or dependency files (e.g., requirements.txt, pyproject.toml) of the affected project.
  2. Update the tornado version to 'tornado>=6.5.9'.
  3. Run the package manager installation command, such as 'pip install -U tornado'.
  4. Validate the fix by attempting to send a GET query string containing more than 1,000 arguments and verifying that the server responds with an HTTP 400 Bad Request.

References


Read the full report for GHSA-3HV7-MJH2-FV65 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)