Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92385.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92385
Upstream
Published
2026-07-14T21:17:02Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-49855 affecting package python-tornado 6.3.3-11
Details

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.

References

Affected packages

Azure Linux:3 / python-tornado

Package

Name
python-tornado
Purl
pkg:rpm/azure-linux/python-tornado

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.3.3-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92385.json"