CVE-2026-82397 | tornadoweb Tornado up to 6.5.7 Request Body Parsing tornado/web.py RequestHandler._execute infinite loop

SecurityVulns

A vulnerability categorized as problematic has been discovered in tornadoweb Tornado up to 6.5.7. Affected by this vulnerability is the function RequestHandler._execute of the file tornado/web.py of the component Request Body Parsing. Such manipulation leads to infinite loop.

This vulnerability is documented as CVE-2026-82397. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More