CVE-2026-31958 is a Denial-of-Service (DoS) vulnerability affecting Tornado, a Python web framework, in versions prior to 6.5.5. The flaw allows an attacker to trigger resource exhaustion by sending a multipart/form-data request with an excessive number of parts, as parsing occurs synchronously on the main thread without an adequate limit. Rated 7.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), this vulnerability can be exploited remotely by an unauthenticated attacker with low complexity, leading to a complete denial of service. There is no evidence of active exploitation, nor are public exploit codes available on platforms like Metasploit or ExploitDB. While not on the CISA KEV catalog, the vulnerability has been noted in community discussions, including GitHub remediation efforts and a SUSE security update.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5.5CPE matchmatch criteria | cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.