CVE Vulnerabilities

CVE-2026-49855

Improper Handling of Highly Compressed Data (Data Amplification)

Published: Jul 14, 2026 | Modified: Jul 16, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.

Weakness

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatpython-tornado-0:6.5.8-0.el10_2.1*
Red Hat Enterprise Linux 9RedHatpython-tornado-0:6.5.8-0.el9_8.1*
Red Hat OpenShift AI 3.3RedHatrhoai/odh-llama-stack-core-rhel9:1789121286*

References