tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
GHSA-8423-8fgw-73vq · CVE-2026-91990
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Description
Summary
parse_multipart_form_data (httputil.py:34) callsdata.split(b"--"+boundary+b"\r\n") before the max_parts check (:35).
A 600KB body with 100k parts creates a 100k-element transient list first,
then rejects transient memory amplification (each split element is a copy).
Pre-auth HTTP DoS.
Root cause
parts = data[:final_boundary_index].split(b"--" + boundary + b"\r\n") # :34 huge list first
if len(parts) > config.max_parts: # :35 check after
raise HTTPInputError("multipart/form-data has too many parts")
PoC
gist: https://gist.github.com/afldl/649861f25d39b53b7edbe0298e171617poc.py + output.txt (100k parts from 600KB transient list).
Fix
Count separators without materializing the list (e.g. data.count(b"--"+boundary) first).
Credit
Reported by afldl, 2026-07.
References
- WEB https://github.com/tornadoweb/tornado/security/advisories/GHSA-8423-8fgw-73vq
- WEB https://github.com/tornadoweb/tornado/pull/3704
- WEB https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05
- WEB https://gist.github.com/afldl/649861f25d39b53b7edbe0298e171617
- PACKAGE https://github.com/tornadoweb/tornado
- WEB https://github.com/tornadoweb/tornado/releases/tag/v6.5.8
Ready to move
Start Securing
Free, no credit card | First findings in minutes