GHSA-3hv7-mjh2-fv65: Tornado: Unbounded query-string argument count allows event-loop-stalling DoS
HTTPServerRequest.__init__ in tornado/httputil.py parses the URL query string via
parse_qs_bytes() with no field-count limit — while the sibling POST-body parsing path
(parse_body_arguments) received a max_num_fields=1000 cap added earlier in this exact
same release (v6.5.8, commit 8d6363ed), explicitly to bound parsing cost for the identical
underlying primitive. This leaves the query-string path with the resource-exhaustion exposure
the body-path fix was meant to close.
File: tornado/httputil.py, line 553 (HTTPServerRequest.__init__)
References
- github.com/advisories/GHSA-3hv7-mjh2-fv65
- github.com/tornadoweb/tornado/commit/03945136ea9746eccf61caf88edae39642e59c93
- github.com/tornadoweb/tornado/commit/8a61dd6005f42733015160f3c23a2bcffe200542
- github.com/tornadoweb/tornado/pull/3719
- github.com/tornadoweb/tornado/releases/tag/v6.5.9
- github.com/tornadoweb/tornado/security/advisories/GHSA-3hv7-mjh2-fv65
Code Behaviors & Features
Detect and mitigate GHSA-3hv7-mjh2-fv65 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →