Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91990

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.

A flaw was found in Tornado. This memory amplification vulnerability exists in the parse_multipart_form_data function, where multipart data is processed before validating the maximum number of parts. A remote attacker can exploit this by sending specially crafted multipart requests with numerous parts. This can lead to the creation of large temporary data structures, exhausting server memory and resulting in a Denial of Service (DoS) for the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Will not fix
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Affected
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Affected
Red Hat Enterprise Linux 10python-tornadoAffected
Red Hat Enterprise Linux 10rhel10/keylime-registrarAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2533953tornado: Tornado: Denial of Service via memory amplification in multipart parsing

EPSS

Процентиль: 35%
0.00412
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 дней назад

(Tornado before 6.5.8 contains a memory amplification vulnerability in ...)

CVSS3: 7.5
nvd
5 дней назад

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.

CVSS3: 7.5
debian
5 дней назад

Tornado before 6.5.8 contains a memory amplification vulnerability in ...

CVSS3: 7.5
github
5 дней назад

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.

EPSS

Процентиль: 35%
0.00412
Низкий

7.5 High

CVSS3