CVE-2026-103262

Description

A flaw was found in Tornado. A remote malicious server can cause a Denial of Service (DoS) when an application using the CurlAsyncHTTPClient component fetches an untrusted web address. Because the client fails to enforce limits on incoming response sizes, the attacker can return a small, highly compressed payload (a decompression bomb) that expands to an enormous size. This unbounded memory consumption exhausts system resources and crashes the application.

Statement

This vulnerability has been rated as Important because an untrusted remote server can remotely terminate an application process through memory exhaustion without requiring credentials. By default, Tornado deploys the SimpleAsyncHTTPClient implementation, which includes built-in thresholds for decompressed and raw payload sizes and remains unaffected by this flaw. However, systems that explicitly configure CurlAsyncHTTPClient—typically enabled for custom proxy routing or advanced transport options—bypass these protections and do not enforce body size constraints. When such client applications fetch resources from compromised or malicious web endpoints, the resulting decompression bomb can consume all available system memory, leading to an immediate denial of service.

Mitigation

Restrict outbound HTTP client requests to trusted destinations and avoid using the CurlAsyncHTTPClient backend when fetching untrusted web content.

1. Application configuration: Configure Tornado applications to utilize the default SimpleAsyncHTTPClient instead of CurlAsyncHTTPClient, provided specialized libcurl functionality (such as custom proxy configurations or specific TLS options) is not required. The default client enforces strict size boundaries on compressed and uncompressed response bodies.
2. Network egress filtering: Implement firewall rules or egress network policies to restrict outbound HTTP/HTTPS connections exclusively to verified, trustworthy endpoints, preventing the client from contacting potentially malicious third-party servers.
3. Operational controls: Ensure that user-supplied or untrusted URLs are validated, sanitized, or rejected before initiating outbound retrieval requests.

Caveats: Switching the HTTP client backend from CurlAsyncHTTPClient to SimpleAsyncHTTPClient may disrupt services that depend on libcurl-specific features. Enforcing egress filtering may block connections to unlisted external services.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.5N/A7.5
Attack VectorNetworkN/ANetwork
Attack ComplexityLowN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityNoneN/ANone
Integrity ImpactNoneN/ANone
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Amplification; DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory)

System resources, CPU and memory, can be quickly consumed. This can lead to poor system performance or system crash.

Frequently Asked Questions

Want to get errata notifications? Sign up here.