GHSA-8423-8fgw-73vq
tornado: multipart split() creates huge temp list before max_parts check -> memory amplification DoS (httputil.py:34)
Quick fix
GHSA-8423-8fgw-73vq — tornado: upgrade to the fixed version with the command below.
pip install --upgrade 'tornado>=6.5.8'Details
## Description
### Summary
`parse_multipart_form_data` (httputil.py:34) calls `data.split(b"--"+boundary+b"\r\n")` **before** the `max_parts` check (:35). A 600KB body with 100k parts creates a 100k-element transient list first, then rejects transient memory amplification (each split element is a copy). Pre-auth HTTP DoS.
### Root cause
```python parts = data[:final_boundary_index].split(b"--" + boundary + b"\r\n") # :34 huge list first if len(parts) > config.max_parts: # :35 check after raise HTTPInputError("multipart/form-data has too many parts") ```
### PoC
gist: https://gist.github.com/afldl/649861f25d39b53b7edbe0298e171617 `poc.py` + `output.txt` (100k parts from 600KB transient list).
### Fix
Count separators without materializing the list (e.g. `data.count(b"--"+boundary)` first).
### Credit
Reported by afldl, 2026-07.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/tornadoweb/tornado/security/advisories/GHSA-8423-8fgw-73vq[WEB]
- https://github.com/tornadoweb/tornado/pull/3704[WEB]
- https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05[WEB]
- https://gist.github.com/afldl/649861f25d39b53b7edbe0298e171617[WEB]
- https://github.com/tornadoweb/tornado[PACKAGE]
- https://github.com/tornadoweb/tornado/releases/tag/v6.5.8[WEB]