Resource exhaustion in Tornado - CVE-2026-31958
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in multipart/form-data parsing on the main thread when processing very large multipart request bodies with many parts. A remote attacker can send a specially crafted multipart/form-data request to cause a denial of service.
The number of multipart parts is limited only by the max_body_size setting.
Affected software
SUSE Linux Enterprise Server 15 SP5
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server 15 SP4
SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Multi-Linux Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Manager Client Tools for SLE
SUSE Multi-Linux Manager Client Tools for SLE
SUSE Multi-Linux Manager Client Tools for Debian
SUSE Linux Enterprise Server for the Raspberry Pi
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
Basesystem Module
Python 3 Module
Systems Management Module
openSUSE Leap
Ubuntu
openEuler
Fedora
SUSE Multi-Linux Manager Client Tools for Ubuntu 22.04
SUSE Multi-Linux Manager Client Tools for Ubuntu 24.04
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
golang-github-QubitProducts-exporter_exporter
golang-github-QubitProducts-exporter_exporter-debuginfo
prometheus-postgres_exporter
prometheus-postgres_exporter-debuginfo
pcs (Red Hat package)
pcs-snmp
pcs
prometheus-blackbox_exporter-debuginfo
prometheus-blackbox_exporter
golang-github-prometheus-alertmanager
golang-github-prometheus-alertmanager-debuginfo
system-user-grafana
system-user-prometheus
golang-github-lusitaniae-apache_exporter
golang-github-lusitaniae-apache_exporter-debuginfo
golang-github-prometheus-node_exporter-debuginfo
golang-github-prometheus-node_exporter
golang-github-boynux-squid_exporter-debuginfo
golang-github-boynux-squid_exporter
golang-github-prometheus-prometheus
golang-github-prometheus-prometheus-debuginfo
python-tornado (Ubuntu package)
python-tornado (Red Hat package)
python-tornado-debuginfo
python-tornado-debugsource
python-tornado
python3-tornado
release-notes-susemanager-proxy
release-notes-susemanager
python3-tornado-debuginfo
spacecmd
mgrctl-bash-completion
mgrctl-zsh-completion
mgrctl
mgrctl-fish-completion
mgrctl-debuginfo
mgrctl-lang
python-tornado-help
python311-tornado6-debuginfo
python311-tornado6
python-tornado6-debugsource
python3-tornado-doc
grafana-debuginfo
grafana
venv-salt-minion
python3-salt-testsuite
salt-zsh-completion
salt-bash-completion
salt-fish-completion
salt
salt-minion
salt-proxy
salt-ssh
salt-syndic
salt-master
salt-transactional-update
salt-api
python3-salt
salt-standalone-formulas-configuration
python311-salt
python311-salt-testsuite
salt-cloud
salt-doc
How to mitigate CVE-2026-31958
golang-github-QubitProducts-exporter_exporter - update to 0.4.0-160002.2.1
golang-github-QubitProducts-exporter_exporter-debuginfo - update to 0.4.0-160002.2.1
prometheus-postgres_exporter - update to 0.10.1-160002.1.1
prometheus-postgres_exporter-debuginfo - update to 0.10.1-160002.1.1
pcs (Red Hat package) - addressed in versions 0.10.12-6.el8_6.13, 0.10.15-4.el8_8.11, 0.11.1-10.el9_0.11
pcs-snmp - update to 0.10.18-2.0.1
pcs - update to 0.10.18-2.0.1
prometheus-blackbox_exporter-debuginfo - update to 0.26.0-160002.1.1
prometheus-blackbox_exporter - update to 0.26.0-160002.1.1
golang-github-prometheus-alertmanager - update to 0.28.1-160002.1.1
golang-github-prometheus-alertmanager-debuginfo - update to 0.28.1-160002.1.1
system-user-grafana - update to 1.0.0-160002.1.1
system-user-prometheus - update to 1.0.0-160002.1.1
golang-github-lusitaniae-apache_exporter - addressed in versions 1.0.10-70002.3.6.1, 1.0.10-80002.3.6.2, 1.0.10-90002.3.6.1, 1.0.10-160002.1.1
golang-github-lusitaniae-apache_exporter-debuginfo - update to 1.0.10-160002.1.1
golang-github-prometheus-node_exporter-debuginfo - update to 1.9.1-160002.1.1
golang-github-prometheus-node_exporter - update to 1.9.1-160002.1.1
golang-github-boynux-squid_exporter-debuginfo - update to 1.13.0-160002.1.1
golang-github-boynux-squid_exporter - update to 1.13.0-160002.1.1
golang-github-prometheus-prometheus - update to 3.5.0-160002.1.1
golang-github-prometheus-prometheus-debuginfo - update to 3.5.0-160002.1.1
python-tornado (Ubuntu package) - addressed in versions 4.2.1-1ubuntu3.1+esm3, 4.5.3-1ubuntu0.2+esm3, 6.0.3+really5.1.1-3ubuntu0.1~esm5, 6.1.0-3ubuntu0.1~esm5, 6.4.0-1ubuntu0.5, 6.4.2-3ubuntu0.3, 6.5.4-0.1ubuntu0.1
python-tornado (Red Hat package) - addressed in versions 4.2.1-5.el7_9.3, 6.4.2-1.el9_4.2, 6.4.2-1.el10_0.2, 6.5.5-1.el9_7.1, 6.5.5-1.el10_1.1
python-tornado-debuginfo - addressed in versions 4.2.1-17.18.1, 4.5.3-150000.3.19.1
python-tornado-debugsource - addressed in versions 4.2.1-17.18.1, 4.5.3-150000.3.19.1
python-tornado - update to 4.2.1-17.18.1
python3-tornado - addressed in versions 4.2.1-17.18.1, 4.5.3-150000.3.19.1
release-notes-susemanager-proxy - update to 4.3.18-150400.3.110.2
release-notes-susemanager - update to 4.3.18-150400.3.154.2
python3-tornado-debuginfo - update to 4.5.3-150000.3.19.1
spacecmd - addressed in versions 5.1.13-70002.3.9.1, 5.1.13-80002.3.9.2, 5.1.13-90002.3.9.1, 5.1.13-120002.3.17.1, 5.1.13-160002.1.1, 5.1.13-220402.3.15.1, 5.1.13-240402.3.20.1
mgrctl-bash-completion - addressed in versions 5.1.26-80002.3.9.2, 5.1.26-90002.3.9.1, 5.1.26-120002.3.17.1, 5.1.26-160002.1.1, 5.1.26-220402.3.15.1, 5.1.26-240402.3.15.1
mgrctl-zsh-completion - addressed in versions 5.1.26-80002.3.9.2, 5.1.26-90002.3.9.1, 5.1.26-120002.3.17.1, 5.1.26-160002.1.1, 5.1.26-220402.3.15.1, 5.1.26-240402.3.15.1
mgrctl - addressed in versions 5.1.26-80002.3.9.2, 5.1.26-90002.3.9.1, 5.1.26-120002.3.17.1, 5.1.26-160002.1.1, 5.1.26-220402.3.15.1, 5.1.26-240402.3.15.1
mgrctl-fish-completion - addressed in versions 5.1.26-120002.3.17.1, 5.1.26-220402.3.15.1, 5.1.26-240402.3.15.1
mgrctl-debuginfo - update to 5.1.26-160002.1.1
mgrctl-lang - update to 5.1.26-160002.1.1
python3-tornado - addressed in versions 6.1-6, 6.5-3
python-tornado-help - addressed in versions 6.1-6, 6.5-3
python-tornado-debugsource - addressed in versions 6.1-6, 6.5-3
python-tornado-debuginfo - addressed in versions 6.1-6, 6.5-3
python-tornado - addressed in versions 6.1-6, 6.5-3
python311-tornado6-debuginfo - update to 6.3.2-150400.9.15.1
python311-tornado6 - update to 6.3.2-150400.9.15.1
python-tornado6-debugsource - update to 6.3.2-150400.9.15.1
python3-tornado - update to 6.5.2-2
python3-tornado-doc - update to 6.5.2-2
python-tornado - addressed in versions 6.5.7-1.fc43, 6.5.7-1.fc44, 6.5.7-1.fc45
grafana-debuginfo - update to 11.6.14+security01-160002.1.1
grafana - update to 11.6.14+security01-160002.1.1
venv-salt-minion - addressed in versions 3006.0-70002.5.12.1, 3006.0-80002.5.12.3, 3006.0-90002.5.12.2, 3006.0-120002.3.20.5, 3006.0-120002.5.12.1, 3006.0-150002.5.12.2, 3006.0-160002.5.1, 3006.0-220402.3.18.1, 3006.0-240402.3.18.1
python3-salt-testsuite - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1
salt-zsh-completion - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-bash-completion - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-fish-completion - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-minion - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-proxy - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-ssh - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-syndic - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-master - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-transactional-update - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
salt-api - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
python3-salt - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1
salt-standalone-formulas-configuration - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
python311-salt - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
python311-salt-testsuite - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1
salt-cloud - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1
salt-doc - addressed in versions 3006.0-150400.8.101.1, 3006.0-150500.4.75.1, 3006.0-150700.14.23.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Tornado
- openEuler 24.03 LTS SP1 update for python-tornado
- openEuler 24.03 LTS update for python-tornado
- openEuler 22.03 LTS SP4 update for python-tornado
- openEuler 24.03 LTS SP3 update for python-tornado
- openEuler 24.03 LTS SP2 update for python-tornado
- SUSE update for python-tornado6
- SUSE update for python-tornado
- SUSE update for python-tornado
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Client Tools and Salt Bundle
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Client Tools
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Salt Bundle
- SUSE update for Security update 5.1.3 for Multi-Linux Manager Salt Bundle
- Anolis OS update for python-tornado
- Anolis OS update for pcs
- Ubuntu update for python-tornado
- Red Hat Enterprise Linux 9 update for pcs
- Red Hat Enterprise Linux 8 update for pcs
- Red Hat Enterprise Linux 8 update for pcs
- Ubuntu update for python-tornado
- Red Hat Enterprise Linux 10 update for python-tornado
- Red Hat Enterprise Linux 9 update for python-tornado
- Red Hat Enterprise Linux 10 update for python-tornado
- Red Hat Enterprise Linux 9 update for python-tornado
- SUSE update for salt
- SUSE update for salt
- SUSE update for salt
- SUSE update for Maintenance update for Multi-Linux Manager 4.3 Release Notes Release Notes
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for python-tornado
- Fedora 45 update for python-tornado
- Fedora 43 update for python-tornado
- Fedora 44 update for python-tornado