Threat Advisory

Tornado Flaw Lets Attackers Stall Event Loop with Huge Urlencoded Requests

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, CVE-2026-82397 with a CVSS score of 7.5, affects Tornado versions less than or equal to 6.5.7, allowing attackers to stall the event loop by sending huge urlencoded requests, leading to denial-of-service against the whole process and impacting business operations due to its single-threaded design and synchronous parsing on the event loop. The flaw type is a denial-of-service vulnerability with an attack vector of network access and no user interaction required. This issue can have significant business impact as it affects the entire server, not just individual requests, making it challenging for businesses to maintain operational continuity.

RECOMMENDATION:

We recommend you to update Tornado to version 6.5.8.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A high-severity vulnerability, CVE-2026-82397 with a CVSS score of 7.5, affects Tornado versions less than or equal to 6.5.7, allowing attackers to stall the event loop by sending huge urlencoded requests, leading to denial-of-service against the whole process and impacting business operations due to its single-threaded design and synchronous parsing on the event loop. The flaw type is a denial-of-service vulnerability with an attack vector of network access and no user interaction required. This issue can have significant business impact as it affects the entire server, not just individual requests, making it challenging for businesses to maintain operational continuity.

RECOMMENDATION:

We recommend you to update Tornado to version 6.5.8.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu