
🚨High - Tornado CurlAsyncHTTPClient gzip Decompression Bomb DoS (CVE-2026-103262) Tornado's tornado.curl_httpclient.CurlAsyncHTTPClient accumulates decompressed data from gzip-encoded responses without bounding output size. A remote attacker can return a crafted decompression bomb to exhaust memory and crash the process (DoS). SimpleHTTPClient is not impacted. 👉Affected: tornado < 6.5.9 | Upgrade to 6.5.9
