Junglewise Threat Intelligence

CVE-2026-49855: Tornado memory exhaustion via gzip decompression amplification

CVE-2026-49855 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: tornado (PyPI). Vendors: PyPI.

Executive brief

Tornado, a popular Python web framework and networking library, is vulnerable to a 'gzip bomb' attack that can crash applications by exhausting their memory. A malicious server or client can send highly compressed data that expands to an enormous size when processed, leading to a denial-of-service (DoS) condition. This affects services using Tornado's asynchronous HTTP client or servers configured to automatically decompress incoming requests.

Technical details

A data amplification vulnerability (CWE-409) exists in Tornado's gzip decompression routines prior to version 6.5.6. While the library enforced limits on the compressed size of incoming data (via Content-Length), it failed to enforce a cumulative limit on the total size of the decompressed output. An attacker can exploit this by providing a 'gzip bomb'—a small compressed payload that expands into a massive amount of data—to a SimpleAsyncHTTPClient or an HTTPServer with decompress_request=True. This leads to uncontrolled memory consumption and a process crash. The fix in 6.5.6 ensures max_body_size is enforced for both compressed and decompressed data.

Affected products

  • tornadoweb Tornado < 6.5.6

Timeline

  • 2026-05-21: patched: Fixes committed to repository
  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-07-14: disclosed: CVE published to NVD

References

Related threats