CVE-2026-103261 | TornadoWeb Tornado up to 6.5.8 Query String HTTPServerRequest.__init__ resource consumption
A vulnerability, which was classified as problematic, was found in TornadoWeb Tornado up to 6.5.8. Impacted is the function HTTPServerRequest.__init__ of the component Query String Handler. Executing a manipulation can lead to resource consumption.
This vulnerability is tracked as CVE-2026-103261. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More