Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop. | |
| Title | Tornado before 6.5.9 Denial of Service via Query String | |
| First Time appeared |
Tornadoweb
Tornadoweb tornado |
|
| Weaknesses | CWE-770 | |
| CPEs | cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tornadoweb
Tornadoweb tornado |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-01T10:42:04.230Z
Reserved: 2026-09-30T10:55:39.869Z
Link: CVE-2026-103261
No data.
Status : Deferred
Published: 2026-10-01T11:17:20.847
Modified: 2026-10-01T11:17:20.997
Link: CVE-2026-103261
No data.
OpenCVE Enrichment
No data.