<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T15:01:23.204385+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-82397</id>
    <title>BELL-CVE-2026-82397</title>
    <updated>2026-10-03T15:01:23.215320+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: py3-tornado, Alpaquita:stream: py3-tornado</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-82397"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-82397</id>
    <title>BREW-jupyterlab-CVE-2026-82397 — Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop</title>
    <updated>2026-10-03T15:01:23.215364+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: jupyterlab</p>
<p>## Summary</p>
<p>Tornado parses `application/x-www-form-urlencoded` bodies with `urllib.parse.parse_qs` and does not pass `max_num_fields`. A body made almost entirely of separators produces tens of millions of fields, and the parse happens on the event loop before the handler runs, so a single request stalls the whole server.</p>
<p>## Where it is</p>
<p>`tornado/escape.py`, at HEAD `e530031405e2154654dedc4c84d5656b557ea310`:</p>
<p>```python
result = urllib.parse.parse_qs(
    qs, keep_blank_values, strict_parsing, encoding="latin1", errors="strict"
)
```</p>
<p>`max_num_fields` is the parameter CPython added for exactly this, and it is absent.</p>
<p>The path to it is entirely server-side and pre-dispatch. `RequestHandler._execute` parses the body at `tornado/web.py:1821`, which reaches `HTTPServerRequest._parse_body` at `tornado/httputil.py:636`, and the urlencoded branch of `parse_body_arguments` calls `parse_qs_bytes` at `tornado/httputil.py:1030`.</p>
<p>The size that reaches it is bounded only by the body cap, which defaults to the stream's `max_buffer_size` of 104857600 at `tornado/iostream.py:239`, applied as the request body default at `tornado/http1connection.py:136-140`. A 100 MB body of separators is around fifty million fields.</p>
<p>## Impact</p>
<p>Denial of service against the whole process, not one request. Tornado is single-threaded and the parse is synchronous on the event loop, so every other connection waits. No authentication is needed if any route accepts a form post, which is the normal case.</p>
<p>## Sug…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-82397"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233</id>
    <title>certfr-2026-avi-1233 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T15:01:23.215412+00:00</updated>
    <content>certfr-2026-avi-1233</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1233"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-cx71098</id>
    <title>CLEANSTART-2026-CX71098 — Tornado is a Python web framework and asynchronous networking library</title>
    <updated>2026-10-03T15:01:23.215436+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>CVE-2026-82397 affects multiple packages. Tornado is a Python web framework and asynchronous networking library. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-cx71098"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-363209</id>
    <title>EUVD-2026-363209</title>
    <updated>2026-10-03T15:01:23.215473+00:00</updated>
    <content>EUVD-2026-363209</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-363209"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82397</id>
    <title>fkie_cve-2026-82397</title>
    <updated>2026-10-03T15:01:23.215497+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, so an unauthenticated request body containing millions of separator-delimited fields can synchronously stall the single-threaded event loop and delay every connection. The body is bounded only by max_buffer_size, which defaults to 104857600 bytes. This issue is fixed in version 6.5.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-82397"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-mpf4-983q-p7j4</id>
    <title>GHSA-mpf4-983q-p7j4 — Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop</title>
    <updated>2026-10-03T15:01:23.215520+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>## Summary</p>
<p>Tornado parses `application/x-www-form-urlencoded` bodies with `urllib.parse.parse_qs` and does not pass `max_num_fields`. A body made almost entirely of separators produces tens of millions of fields, and the parse happens on the event loop before the handler runs, so a single request stalls the whole server.</p>
<p>## Where it is</p>
<p>`tornado/escape.py`, at HEAD `e530031405e2154654dedc4c84d5656b557ea310`:</p>
<p>```python
result = urllib.parse.parse_qs(
    qs, keep_blank_values, strict_parsing, encoding="latin1", errors="strict"
)
```</p>
<p>`max_num_fields` is the parameter CPython added for exactly this, and it is absent.</p>
<p>The path to it is entirely server-side and pre-dispatch. `RequestHandler._execute` parses the body at `tornado/web.py:1821`, which reaches `HTTPServerRequest._parse_body` at `tornado/httputil.py:636`, and the urlencoded branch of `parse_body_arguments` calls `parse_qs_bytes` at `tornado/httputil.py:1030`.</p>
<p>The size that reaches it is bounded only by the body cap, which defaults to the stream's `max_buffer_size` of 104857600 at `tornado/iostream.py:239`, applied as the request body default at `tornado/http1connection.py:136-140`. A 100 MB body of separators is around fifty million fields.</p>
<p>## Impact</p>
<p>Denial of service against the whole process, not one request. Tornado is single-threaded and the parse is synchronous on the event loop, so every other connection waits. No authentication is needed if any route accepts a form post, which is the normal case.</p>
<p>## Sug…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-mpf4-983q-p7j4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3971</id>
    <title>OESA-2026-3971 — python-tornado security update</title>
    <updated>2026-10-03T15:01:23.215558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: python-tornado</p>
<p>Tornado is an open source version of the scalable, non-blocking web server and tools.

Security Fix(es):</p>
<p>Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, so an unauthenticated request body containing millions of separator-delimited fields can synchronously stall the single-threaded event loop and delay every connection. The body is bounded only by max_buffer_size, which defaults to 104857600 bytes. This issue is fixed in version 6.5.8.(CVE-2026-82397)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3971"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3928</id>
    <title>PYSEC-2026-3928 — Tornado: Urlencoded body parsing omits max_num_fields, so one request can stall the event loop</title>
    <updated>2026-10-03T15:01:23.215581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>## Summary</p>
<p>Tornado parses `application/x-www-form-urlencoded` bodies with `urllib.parse.parse_qs` and does not pass `max_num_fields`. A body made almost entirely of separators produces tens of millions of fields, and the parse happens on the event loop before the handler runs, so a single request stalls the whole server.</p>
<p>## Where it is</p>
<p>`tornado/escape.py`, at HEAD `e530031405e2154654dedc4c84d5656b557ea310`:</p>
<p>```python
result = urllib.parse.parse_qs(
    qs, keep_blank_values, strict_parsing, encoding="latin1", errors="strict"
)
```</p>
<p>`max_num_fields` is the parameter CPython added for exactly this, and it is absent.</p>
<p>The path to it is entirely server-side and pre-dispatch. `RequestHandler._execute` parses the body at `tornado/web.py:1821`, which reaches `HTTPServerRequest._parse_body` at `tornado/httputil.py:636`, and the urlencoded branch of `parse_body_arguments` calls `parse_qs_bytes` at `tornado/httputil.py:1030`.</p>
<p>The size that reaches it is bounded only by the body cap, which defaults to the stream's `max_buffer_size` of 104857600 at `tornado/iostream.py:239`, applied as the request body default at `tornado/http1connection.py:136-140`. A 100 MB body of separators is around fifty million fields.</p>
<p>## Impact</p>
<p>Denial of service against the whole process, not one request. Tornado is single-threaded and the parse is synchronous on the event loop, so every other connection waits. No authentication is needed if any route accepts a form post, which is the normal case.</p>
<p>## Sug…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3928"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23523-1</id>
    <title>SUSE-SU-2026:23523-1 — Security update for python-tornado6</title>
    <updated>2026-10-03T15:01:23.215617+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-tornado6</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23523-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82397</id>
    <title>UBUNTU-CVE-2026-82397</title>
    <updated>2026-10-03T15:01:23.215632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado</p>
<p>Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, so an unauthenticated request body containing millions of separator-delimited fields can synchronously stall the single-threaded event loop and delay every connection. The body is bounded only by max_buffer_size, which defaults to 104857600 bytes. This issue is fixed in version 6.5.8.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-82397"/>
  </entry>
</feed>
