Allocation of Resources Without Limits or Throttling in Tornado - #VU149940
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits in the HTTPServerRequest.__init__ query-string parsing path when processing a GET request with a query string containing thousands of fields. A remote attacker can send a specially crafted GET request with a high number of query-string fields to cause a denial of service.