Executive brief
Tornado, a popular Python web framework and networking library, is vulnerable to a 'gzip bomb' attack that can crash applications by exhausting their memory. A malicious server or client can send highly compressed data that expands to an enormous size when processed, leading to a denial-of-service (DoS) condition. This affects services using Tornado's asynchronous HTTP client or servers configured to automatically decompress incoming requests.
Technical details
A data amplification vulnerability (CWE-409) exists in Tornado's gzip decompression routines prior to version 6.5.6. While the library enforced limits on the compressed size of incoming data (via Content-Length), it failed to enforce a cumulative limit on the total size of the decompressed output. An attacker can exploit this by providing a 'gzip bomb'—a small compressed payload that expands into a massive amount of data—to a SimpleAsyncHTTPClient or an HTTPServer with decompress_request=True. This leads to uncontrolled memory consumption and a process crash. The fix in 6.5.6 ensures max_body_size is enforced for both compressed and decompressed data.
Affected products
- tornadoweb Tornado < 6.5.6
Timeline
- 2026-05-21: patched: Fixes committed to repository
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-07-14: disclosed: CVE published to NVD