---
id: CVE-2026-49855
title: >-
  tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory
  consumption (CVE-2026-49855)
summary: >-
  A flaw was found in Tornado, a Python web framework and asynchronous
  networking library. Its gzip decompression routines process data in
  limited-size chunks but do not enforce an overall limit on the total
  accumulated decompressed data. Th…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe:
  - CWE-770
  - CWE-409
vendor: Red Hat
product: Red Hat OpenShift AI (RHOAI)
affected:
  - exploit_intelligence
  - enterprise_linux 10
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openshift_container_platform 4
  - openstack_platform 16.2
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
published: '2026-07-14'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T15:45:00+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49855.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49855.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-49855'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2500686'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-49855'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49855'
  - url: >-
      https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff
  - url: 'https://github.com/tornadoweb/tornado/pull/3626'
  - url: >-
      https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56
  - url: 'https://access.redhat.com/errata/RHSA-2026:67147'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67146'
  - url: 'https://github.com/tornadoweb/tornado'
  - url: 'https://github.com/advisories/GHSA-mgf9-4vpg-hj56'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00609
epssPercentile: 0.4685
aliases:
  - GHSA-mgf9-4vpg-hj56
  - PYSEC-2026-3389
ecosystem: pip
ingestedAt: '2026-07-07T15:41:58.659Z'
---

## Overview

A flaw was found in Tornado, a Python web framework and asynchronous networking library. Its gzip decompression routines process data in limited-size chunks but do not enforce an overall limit on the total accumulated decompressed data. This vulnerability allows a malicious server to consume effectively unlimited memory, leading to a denial of service, when accessed by a client using SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request set to true.

## Vendor advisories

- **RHSA-2026:67147** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67147)
- **RHSA-2026:67146** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67146)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4, … · no fix planned: Exploit Intelligence, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49855.json)

**tornado: Tornado: Denial of Service via uncontrolled gzip decompression memory consumption** — rated Important by Red Hat. Released 2026-07-14, updated 2026-09-22.

Affected:

- Exploit Intelligence
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenStack Platform 16.2

Fixed:

- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream (v. 9)

No fix planned:

- Exploit Intelligence
- Red Hat Enterprise Linux 10
- Red Hat Enterprise Linux 9
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4
- Red Hat OpenStack Platform 16.2

Not affected:

- Lightspeed Core
- Migration Toolkit for Applications 8
- OpenShift Lightspeed
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux 8
- Red Hat OpenShift AI (RHOAI)

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67147
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:67146

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-49855)

Affected packages:

- `tornado < 6.5.6`

Patched in:

- `tornado 6.5.6`

Source: https://osv.dev/vulnerability/GHSA-mgf9-4vpg-hj56
