DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-CHX6-46F5-W4VP: GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient

GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient

Vulnerability ID: GHSA-CHX6-46F5-W4VP
CVSS Score: 7.5
Published: 2026-09-30

A critical uncontrolled resource consumption vulnerability exists in the Tornado web server's libcurl-based HTTP client (CurlAsyncHTTPClient). When processing highly compressed responses with response decompression enabled, the client experiences unbounded memory growth. This leads to host memory exhaustion and denial of service via application crashes.

TL;DR

Tornado's CurlAsyncHTTPClient lacks size limits and backpressure during decompression, allowing a remote server to trigger process termination via memory exhaustion using a decompression bomb.


Technical Details

  • CWE ID: CWE-409, CWE-400
  • Attack Vector: Network (Unauthenticated Upstream Server)
  • CVSS v3.1: 7.5 (High)
  • Exploit Status: Proof of Concept (PoC) available
  • Impact: Denial of Service (OOM Crash)
  • Affected Component: tornado.curl_httpclient.CurlAsyncHTTPClient

Affected Systems

  • Tornado CurlAsyncHTTPClient
  • Tornado: < 6.5.9 (Fixed in: 6.5.9)
  • Tornado: == 6.6.0.dev1 (Fixed in: 6.6.0)

Code Analysis

Commit: 15f0560

Streaming callback memory limit implementation

Commit: aa2eb0d

Buffered mode max_body_size limits

Commit: 6564e0a

Applying max_body_size to streaming executions

Commit: e412435

Version 6.5.9 stable backport of memory limit fixes

Mitigation Strategies

  • Upgrade Tornado to 6.5.9 or 6.6.0.
  • Switch backend HTTP client from CurlAsyncHTTPClient to SimpleAsyncHTTPClient.
  • Disable automatic decompression (decompress_response=False) for untrusted upstream URLs.

Remediation Steps:

  1. Run 'pip install --upgrade tornado>=6.5.9' to patch the environment.
  2. Verify codebases for uses of 'tornado.curl_httpclient.CurlAsyncHTTPClient' and transition backends if upgrade is delayed.
  3. Ensure HTTP clients fetch data with explicit size limits and handle decompression payloads downstream with safety bounds.

References


Read the full report for GHSA-CHX6-46F5-W4VP on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)