Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | RedHat | python-tornado-0:6.5.8-0.el10_2.1 | * |
| Red Hat Enterprise Linux 9 | RedHat | python-tornado-0:6.5.8-0.el9_8.1 | * |
| Red Hat OpenShift AI 3.3 | RedHat | rhoai/odh-llama-stack-core-rhel9:1789121286 | * |