GHSA-chx6-46f5-w4vp: tornado: CurlAsyncHTTPClient enforces no response-size limit — decompression bomb drives unbounded memory accumulation to OOM
An unbounded memory accumulation (decompression bomb) in tornado.curl_httpclient.CurlAsyncHTTPClient — the client-side sibling gap of CVE-2026-49855 — verified end-to-end on the 2026-08-15 master snapshot (6.6.dev1) and present unchanged in the latest release tag v6.5.8 and on master (checked 2026-08-17). When a Tornado application configures the curl client (the documented deployment for proxy support / advanced TLS options) and fetch()es an attacker-chosen or attacker-compromised URL with default decompress_response=True, a malicious server replying Content-Encoding: gzip with a ~2.8 MB wire bomb drove the client’s RSS from 30,884 kB to 1,032,100 kB (~1008 MB) in 3.18 s (~350 MB/s, monotonic, no plateau) until the kernel OOM-killed the process (exit 137, cgroup OOMKilled=true) — with the transfer only 67% complete and no client-side size check ever intervening: curl_httpclient.py contains zero occurrences of max_body_size/MAXFILESIZE. The identical bomb against the default SimpleAsyncHTTPClient fails cleanly at ~65 MB, because every size gate CVE-2026-49855 added (compressed CL, chunked total, cumulative decompressed size — http1connection.py:620,676,742) lives in code the curl client never executes. This is a distinct component from the published advisory (which fixed _GzipMessageDelegate/SimpleAsyncHTTPClient only) and from the other curl-client advisories (credential handle-reuse GHSA-pw6j-qg29-8w7f, header CRLF GHSA-w235-7p84-xx57); the file’s full commit history (latest 2026-06-17) shows no response-size work.
References
- github.com/advisories/GHSA-chx6-46f5-w4vp
- github.com/tornadoweb/tornado/commit/15f056080d8e456f92cca8ad0c33e5a5480414ac
- github.com/tornadoweb/tornado/commit/6564e0a0922c16f239d3a18adccd04736e380c89
- github.com/tornadoweb/tornado/commit/aa2eb0d989716ac00fe8d7a9919b81c1eccd6ec4
- github.com/tornadoweb/tornado/commit/e412435febba4569c552c5c9054f1bf92bd171a9
- github.com/tornadoweb/tornado/pull/3719
- github.com/tornadoweb/tornado/releases/tag/v6.5.9
- github.com/tornadoweb/tornado/security/advisories/GHSA-chx6-46f5-w4vp
Code Behaviors & Features
Detect and mitigate GHSA-chx6-46f5-w4vp with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →