{"id":"AZL-103107","summary":"CVE-2026-91990 affecting package python-tornado 6.3.3-11","details":"Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server memory and causing denial of service.","modified":"2026-09-19T14:16:04.385449845Z","published":"2026-09-15T16:17:58Z","upstream":["CVE-2026-91990"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91990"}],"affected":[{"package":{"name":"python-tornado","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-tornado"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.3.3-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-103107.json"}}],"schema_version":"1.9.0"}