tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler
cve CVE-2026-103263 3 sources, 3 claims · Watch
Red Hat writes:
tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler the claim
tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | tornadoweb/tornadoNVD says “tornadoweb · tornado” |
| made_by | tornadowebNVD says “tornadoweb” |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss | GitHub advisories | 5.9receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-103263",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-59",
"name": "Improper Link Resolution Before File Access ('Link Following')"
}
],
"description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
"ghsa_id": "GHSA-4cjq-6jh9-w2f5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4cjq-6jh9-w2f5"
},
{
"type": "CVE",
"value": "CVE-2026-103263"
}
],
"nvd_published_at": "2026-10-01T11:17:21Z",
"published_at": "2026-10-01T12:31:17Z",
"references": [
"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
"https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
"https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
"https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
"https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
"type": "unreviewed",
"updated_at": "2026-10-01T12:31:18Z",
"url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Cvss cvss | NVD | 5.9receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:pypi/tornado",
"product": "tornado",
"vendor": "tornadoweb",
"versions": [
{
"lessThan": "6.5.9",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.5.9",
"versionType": "semver"
}
]
}
],
"source": "disclosure@vulncheck.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user."
}
],
"id": "CVE-2026-103263",
"lastModified": "2026-10-01T20:17:23.097",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6,
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-103263",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:29:31.769581Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T11:17:21.233",
"references": [
{
"source": "disclosure@vulncheck.com",
"url": "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
}
],
"sourceIdentifier": "disclosure@vulncheck.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-59"
}
],
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
} | — |
| Cvss cvss | Red Hat | 5.9receipt
What the source handed over{
"CVE": "CVE-2026-103263",
"CWE": "CWE-59",
"advisories": [],
"affected_packages": [],
"bugzilla": "2544519",
"bugzilla_description": "tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler",
"cvss3_score": "5.9",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-01T10:42:05Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-103263.json",
"severity": "moderate"
} | — |
| Cwe cwe | GitHub advisories | CWE-59receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-103263",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-59",
"name": "Improper Link Resolution Before File Access ('Link Following')"
}
],
"description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
"ghsa_id": "GHSA-4cjq-6jh9-w2f5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4cjq-6jh9-w2f5"
},
{
"type": "CVE",
"value": "CVE-2026-103263"
}
],
"nvd_published_at": "2026-10-01T11:17:21Z",
"published_at": "2026-10-01T12:31:17Z",
"references": [
"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
"https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
"https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
"https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
"https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
"type": "unreviewed",
"updated_at": "2026-10-01T12:31:18Z",
"url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Cwe cwe | Red Hat | CWE-59receipt
What the source handed over{
"CVE": "CVE-2026-103263",
"CWE": "CWE-59",
"advisories": [],
"affected_packages": [],
"bugzilla": "2544519",
"bugzilla_description": "tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler",
"cvss3_score": "5.9",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-01T10:42:05Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-103263.json",
"severity": "moderate"
} | — |
| Product product | NVD | tornadoreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:pypi/tornado",
"product": "tornado",
"vendor": "tornadoweb",
"versions": [
{
"lessThan": "6.5.9",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.5.9",
"versionType": "semver"
}
]
}
],
"source": "disclosure@vulncheck.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user."
}
],
"id": "CVE-2026-103263",
"lastModified": "2026-10-01T20:17:23.097",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6,
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-103263",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:29:31.769581Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T11:17:21.233",
"references": [
{
"source": "disclosure@vulncheck.com",
"url": "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
}
],
"sourceIdentifier": "disclosure@vulncheck.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-59"
}
],
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
} | — |
| Severity severity conflict | GitHub advisories | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-103263",
"cvss": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 5.9,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
"cvss_v4": {
"score": 8.2,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-59",
"name": "Improper Link Resolution Before File Access ('Link Following')"
}
],
"description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
"ghsa_id": "GHSA-4cjq-6jh9-w2f5",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-4cjq-6jh9-w2f5"
},
{
"type": "CVE",
"value": "CVE-2026-103263"
}
],
"nvd_published_at": "2026-10-01T11:17:21Z",
"published_at": "2026-10-01T12:31:17Z",
"references": [
"https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
"https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
"https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
"https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
"https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
"type": "unreviewed",
"updated_at": "2026-10-01T12:31:18Z",
"url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Severity severity conflict | Red Hat | moderate A flaw that is harder to exploit, or whose impact is limited. receipt
What the source handed over{
"CVE": "CVE-2026-103263",
"CWE": "CWE-59",
"advisories": [],
"affected_packages": [],
"bugzilla": "2544519",
"bugzilla_description": "tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler",
"cvss3_score": "5.9",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2026-10-01T10:42:05Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-103263.json",
"severity": "moderate"
} | medium |
| Status status | NVD | Deferredreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:pypi/tornado",
"product": "tornado",
"vendor": "tornadoweb",
"versions": [
{
"lessThan": "6.5.9",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.5.9",
"versionType": "semver"
}
]
}
],
"source": "disclosure@vulncheck.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user."
}
],
"id": "CVE-2026-103263",
"lastModified": "2026-10-01T20:17:23.097",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6,
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-103263",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:29:31.769581Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T11:17:21.233",
"references": [
{
"source": "disclosure@vulncheck.com",
"url": "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
}
],
"sourceIdentifier": "disclosure@vulncheck.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-59"
}
],
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
} | — |
| Vendor vendor | NVD | tornadowebreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:pypi/tornado",
"product": "tornado",
"vendor": "tornadoweb",
"versions": [
{
"lessThan": "6.5.9",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.5.9",
"versionType": "semver"
}
]
}
],
"source": "disclosure@vulncheck.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user."
}
],
"id": "CVE-2026-103263",
"lastModified": "2026-10-01T20:17:23.097",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 3.6,
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"cvssMetricV40": [
{
"cvssData": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"availabilityRequirement": "NOT_DEFINED",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"exploitMaturity": "NOT_DEFINED",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-103263",
"options": [
{
"exploitation": "poc"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T19:29:31.769581Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T11:17:21.233",
"references": [
{
"source": "disclosure@vulncheck.com",
"url": "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
},
{
"source": "disclosure@vulncheck.com",
"url": "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink"
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
}
],
"sourceIdentifier": "disclosure@vulncheck.com",
"vulnStatus": "Deferred",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-59"
}
],
"source": "disclosure@vulncheck.com",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler zetlyn/cve-redhat · 2026-10-01 | cvss 5.9 cwe CWE-59 severity moderate | source |
| Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user. zetlyn/cve-nvd · 2026-10-01 | cvss 5.9 product tornado status Deferred vendor tornadoweb | source |
| Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows... zetlyn/cve-ghsa · 2026-10-01 | cvss 5.9 cwe CWE-59 severity high | source |