{"id":"AZL-105372","summary":"CVE-2026-103261 affecting package python-tornado 6.3.3-11","details":"Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with thousands of query parameters. Attackers can send unauthenticated GET requests with unbounded query-string field counts to degrade response times for all clients sharing the same IOLoop.","modified":"2026-10-05T05:32:41Z","published":"2026-10-01T11:17:20Z","upstream":["CVE-2026-103261"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-103261"}],"affected":[{"package":{"name":"python-tornado","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/python-tornado"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.3.3-11"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105372.json"}}],"schema_version":"1.9.0"}