Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-31958

Опубликовано: 11 мар. 2026
Источник: debian
EPSS Низкий

Описание

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-tornadounfixedpackage

Примечания

  • https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc

  • Fixed by: https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839 (v6.5.5)

EPSS

Процентиль: 6%
0.00023
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
16 дней назад

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.

CVSS3: 5.3
redhat
16 дней назад

A flaw was found in tornado-python. A remote attacker can exploit this vulnerability by sending a specially crafted, very large multipart body with numerous parts. Because the parsing of these large bodies occurs synchronously on the main thread, it can consume excessive resources, leading to a denial of service (DoS) for the application.

CVSS3: 7.5
nvd
16 дней назад

Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this creates the possibility of denial-of-service due to the cost of parsing very large multipart bodies with many parts. This vulnerability is fixed in 6.5.5.

github
15 дней назад

Tornado is vulnerable to DoS due to too many multipart parts

EPSS

Процентиль: 6%
0.00023
Низкий