mediumVulnerability

GHSA-8423-8fgw-73vq

## Description ### Summary `parse_multipart_form_data` (httputil.py:34) calls `data.split(b"--"+boundary+b"\r\n")` **before** the `max_parts` check (:35). A 600KB body with 100k parts creates a 100k-element transient list first, then rejects transient memory amplification (each split element is a copy). Pre-auth HTTP DoS. ### Root cause ```python parts = data[:final_boundary_index].split(b"--" + boundary + b"\r\n") # :34 huge list first if len(parts) > config.max_parts: # :35 check after raise HTTPInputError("multipart/form-data has too many parts") ``` ### PoC gist: https://gist.github.com/afldl/649861f25d39b53b7edbe0298e171617 `poc.py` + `output.txt` (100k parts from 600KB transient list). ### Fix Count separators without materializing the list (e.g. `data.count(b"--"+boundary)` first). ### Credit Reported by afldl, 2026-07.

Properties

ghsa_id
GHSA-8423-8fgw-73vq
severity
medium
summary
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
cve_id
GHSA-8423-8fgw-73vq
is_ghsa_only
true
ghsa_published
2026-09-01T20:17:38Z
source_url
https://github.com/advisories/GHSA-8423-8fgw-73vq
ghsa_updated
2026-09-01T20:17:39Z

Related Entities (4)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/tornado

AFFECTS (1)

[Software]pip/tornado

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8423-8fgw-73vq — Ninja Signal Threat Intelligence | Ninja Signal