OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-103262

HIGH · CVSS 7.5 EPSS 0.53% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Tornado versions prior to 6.5.9 are vulnerable to an unbounded memory accumulation flaw in CurlAsyncHTTPClient, which can be exploited by remote attackers to trigger a denial of service. By sending a gzip-encoded decompression bomb, attackers can cause excessive memory usage, ultimately leading to application crashes due to out-of-memory conditions. Organizations using affected Tornado versions should prioritize patching to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103262
Severity
HIGH
CVSS
7.5
EPSS
0.53%

Original NVD Description

Tornado versions before 6.5.9 contain an unbounded memory accumulation vulnerability in CurlAsyncHTTPClient that allows remote attackers to cause denial of service by sending a compressed response. Attackers can send a gzip-encoded decompression bomb that accumulates in memory without size limits, causing the application process to be killed by out-of-memory conditions.