#1149712 python-tornado: CVE-2026-103261 CVE-2026-103262 CVE-2026-103263

Package:
src:python-tornado
Source:
src:python-tornado
Submitter:
Salvatore Bonaccorso
Date:
2026-10-02 15:01:07 UTC
Severity:
normal
Tags:
#1149712#5
Date:
2026-10-02 14:48:26 UTC
From:
To:
Hi,

The following vulnerabilities were published for python-tornado.

CVE-2026-103261[0]:
| Tornado before 6.5.9 fails to limit the number of query string
| fields in HTTPServerRequest.__init__, allowing remote attackers to
| cause event-loop stalling by sending requests with thousands of
| query parameters. Attackers can send unauthenticated GET requests
| with unbounded query-string field counts to degrade response times
| for all clients sharing the same IOLoop.


CVE-2026-103262[1]:
| Tornado versions before 6.5.9 contain an unbounded memory
| accumulation vulnerability in CurlAsyncHTTPClient that allows remote
| attackers to cause denial of service by sending a compressed
| response. Attackers can send a gzip-encoded decompression bomb that
| accumulates in memory without size limits, causing the application
| process to be killed by out-of-memory conditions.


CVE-2026-103263[2]:
| Tornado before 6.5.9 contains a path traversal vulnerability in
| StaticFileHandler that follows symbolic links inside the static root
| without confirming the resolved target stays within it. When a
| symlink pointing outside the static directory exists inside it,
| unauthenticated attackers can request it to read files such as
| configuration files, private keys, and application secrets
| accessible to the process user.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-103261
https://www.cve.org/CVERecord?id=CVE-2026-103261
[1] https://security-tracker.debian.org/tracker/CVE-2026-103262
https://www.cve.org/CVERecord?id=CVE-2026-103262
[2] https://security-tracker.debian.org/tracker/CVE-2026-103263
https://www.cve.org/CVERecord?id=CVE-2026-103263

Regards,
Salvatore