{"id":"CVE-2026-49855","title":"tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption (CVE-2026-49855)","summary":"A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. Th…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":["CWE-770","CWE-409"],"vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["exploit_intelligence","migration_toolkit_for_applications 8","enterprise_linux 10","enterprise_linux 9","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","openshift_container_platform 4","openstack_platform 16.2","enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_9"],"patched":["enterprise_linux_appstream_v_10","enterprise_linux_appstream_v_9"],"published":"2026-07-14","updated":"2026-09-15","sourceUpdated":"2026-09-15T14:12:17+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49855.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49855.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-49855"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2500686"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-49855"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49855"},{"url":"https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff"},{"url":"https://github.com/tornadoweb/tornado/pull/3626"},{"url":"https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56"},{"url":"https://access.redhat.com/errata/RHSA-2026:67147"},{"url":"https://access.redhat.com/errata/RHSA-2026:67146"},{"url":"https://github.com/tornadoweb/tornado"},{"url":"https://github.com/advisories/GHSA-mgf9-4vpg-hj56"}],"tags":["csaf","vex","red-hat","osv","pip","ghsa"],"epss":0.00572,"epssPercentile":0.45776,"aliases":["GHSA-mgf9-4vpg-hj56","PYSEC-2026-3389"],"ecosystem":"pip","ingestedAt":"2026-07-07T15:41:58.659Z","slug":"CVE-2026-49855","body":"## Overview\n\nA flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. This vulnerability allows a malicious server to consume effectively unlimited memory, leading to a denial of service, when accessed by a client using SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request set to true.\n\n## Vendor advisories\n\n- **RHSA-2026:67147** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67147)\n- **RHSA-2026:67146** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67146)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Exploit Intelligence, Migration Toolkit for Applications 8, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, … · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49855.json)\n\n**tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption** — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-15.\n\nAffected:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenStack Platform 16.2\n\nFixed:\n\n- Red Hat Enterprise Linux AppStream (v. 10)\n- Red Hat Enterprise Linux AppStream (v. 9)\n\nNo fix planned:\n\n- Exploit Intelligence\n- Migration Toolkit for Applications 8\n- Red Hat Enterprise Linux 10\n- Red Hat Enterprise Linux 9\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat OpenShift Container Platform 4\n- Red Hat OpenStack Platform 16.2\n\nNot affected:\n\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux 8\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67147\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67146\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.\n\n## Package advisory (CVE-2026-49855)\n\nAffected packages:\n\n- `tornado < 6.5.6`\n\nPatched in:\n\n- `tornado 6.5.6`\n\nSource: https://osv.dev/vulnerability/GHSA-mgf9-4vpg-hj56","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}