GHSA-CHX6-46F5-W4VP: Uncontrolled Resource Consumption in Tornado CurlAsyncHTTPClient
Vulnerability ID: GHSA-CHX6-46F5-W4VP
CVSS Score: 7.5
Published: 2026-09-30
A critical uncontrolled resource consumption vulnerability exists in the Tornado web server's libcurl-based HTTP client (CurlAsyncHTTPClient). When processing highly compressed responses with response decompression enabled, the client experiences unbounded memory growth. This leads to host memory exhaustion and denial of service via application crashes.
TL;DR
Tornado's CurlAsyncHTTPClient lacks size limits and backpressure during decompression, allowing a remote server to trigger process termination via memory exhaustion using a decompression bomb.
Technical Details
- CWE ID: CWE-409, CWE-400
- Attack Vector: Network (Unauthenticated Upstream Server)
- CVSS v3.1: 7.5 (High)
- Exploit Status: Proof of Concept (PoC) available
- Impact: Denial of Service (OOM Crash)
- Affected Component: tornado.curl_httpclient.CurlAsyncHTTPClient
Affected Systems
- Tornado CurlAsyncHTTPClient
-
Tornado: < 6.5.9 (Fixed in:
6.5.9) -
Tornado: == 6.6.0.dev1 (Fixed in:
6.6.0)
Code Analysis
Commit: 15f0560
Streaming callback memory limit implementation
Commit: aa2eb0d
Buffered mode max_body_size limits
Commit: 6564e0a
Applying max_body_size to streaming executions
Commit: e412435
Version 6.5.9 stable backport of memory limit fixes
Mitigation Strategies
- Upgrade Tornado to 6.5.9 or 6.6.0.
- Switch backend HTTP client from CurlAsyncHTTPClient to SimpleAsyncHTTPClient.
- Disable automatic decompression (decompress_response=False) for untrusted upstream URLs.
Remediation Steps:
- Run 'pip install --upgrade tornado>=6.5.9' to patch the environment.
- Verify codebases for uses of 'tornado.curl_httpclient.CurlAsyncHTTPClient' and transition backends if upgrade is delayed.
- Ensure HTTP clients fetch data with explicit size limits and handle decompression payloads downstream with safety bounds.
References
Read the full report for GHSA-CHX6-46F5-W4VP on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)