CVE-2026-103262
Description
A flaw was found in Tornado. A remote malicious server can cause a Denial of Service (DoS) when an application using the CurlAsyncHTTPClient component fetches an untrusted web address. Because the client fails to enforce limits on incoming response sizes, the attacker can return a small, highly compressed payload (a decompression bomb) that expands to an enormous size. This unbounded memory consumption exhausts system resources and crashes the application.
Statement
This vulnerability has been rated as Important because an untrusted remote server can remotely terminate an application process through memory exhaustion without requiring credentials. By default, Tornado deploys the SimpleAsyncHTTPClient implementation, which includes built-in thresholds for decompressed and raw payload sizes and remains unaffected by this flaw. However, systems that explicitly configure CurlAsyncHTTPClient—typically enabled for custom proxy routing or advanced transport options—bypass these protections and do not enforce body size constraints. When such client applications fetch resources from compromised or malicious web endpoints, the resulting decompression bomb can consume all available system memory, leading to an immediate denial of service.
Mitigation
Restrict outbound HTTP client requests to trusted destinations and avoid using the CurlAsyncHTTPClient backend when fetching untrusted web content.
1. Application configuration: Configure Tornado applications to utilize the default SimpleAsyncHTTPClient instead of CurlAsyncHTTPClient, provided specialized libcurl functionality (such as custom proxy configurations or specific TLS options) is not required. The default client enforces strict size boundaries on compressed and uncompressed response bodies.
2. Network egress filtering: Implement firewall rules or egress network policies to restrict outbound HTTP/HTTPS connections exclusively to verified, trustworthy endpoints, preventing the client from contacting potentially malicious third-party servers.
3. Operational controls: Ensure that user-supplied or untrusted URLs are validated, sanitized, or rejected before initiating outbound retrieval requests.
Caveats: Switching the HTTP client backend from CurlAsyncHTTPClient to SimpleAsyncHTTPClient may disrupt services that depend on libcurl-specific features. Enforcing egress filtering may block connections to unlisted external services.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 7.5 | N/A | 7.5 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | None | N/A | None |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | None | N/A | None |
| Availability Impact | High | N/A | High |
Vector
Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Amplification; DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory)
System resources, CPU and memory, can be quickly consumed. This can lead to poor system performance or system crash.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.