GHSA-8423-8fgw-73vq
## Description ### Summary `parse_multipart_form_data` (httputil.py:34) calls `data.split(b"--"+boundary+b"\r\n")` **before** the `max_parts` check (:35). A 600KB body with 100k parts creates a 100k-element transient list first, then rejects transient memory amplification (each split element is a copy). Pre-auth HTTP DoS. ### Root cause ```python parts = data[:final_boundary_index].split(b"--" + boundary + b"\r\n") # :34 huge list first if len(parts) > config.max_parts: # :35 check after raise HTTPInputError("multipart/form-data has too many parts") ``` ### PoC gist: https://gist.github.com/afldl/649861f25d39b53b7edbe0298e171617 `poc.py` + `output.txt` (100k parts from 600KB transient list). ### Fix Count separators without materializing the list (e.g. `data.count(b"--"+boundary)` first). ### Credit Reported by afldl, 2026-07.
Properties
- ghsa_id
- GHSA-8423-8fgw-73vq
- severity
- medium
- summary
- tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
- cve_id
- GHSA-8423-8fgw-73vq
- is_ghsa_only
- true
- ghsa_published
- 2026-09-01T20:17:38Z
- source_url
- https://github.com/advisories/GHSA-8423-8fgw-73vq
- ghsa_updated
- 2026-09-01T20:17:39Z
Related Entities (4)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph