tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler

cve CVE-2026-103263 3 sources, 3 claims · Watch

Red Hat writes:
tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectstornadoweb/tornado
NVD says “tornadoweb · tornado”
made_bytornadoweb
NVD says “tornadoweb”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
GitHub advisories5.9
receipt
Source
GitHub advisories
Its words
5.9
Read by
field:cvss.score
Said since
2026-10-02 11:59 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103263",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-59",
      "name": "Improper Link Resolution Before File Access ('Link Following')"
    }
  ],
  "description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
  "ghsa_id": "GHSA-4cjq-6jh9-w2f5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4cjq-6jh9-w2f5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103263"
    }
  ],
  "nvd_published_at": "2026-10-01T11:17:21Z",
  "published_at": "2026-10-01T12:31:17Z",
  "references": [
    "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
    "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
    "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
    "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:18Z",
  "url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cvss
cvss
NVD5.9
receipt
Source
NVD
Its words
5.9
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:pypi/tornado",
            "product": "tornado",
            "vendor": "tornadoweb",
            "versions": [
              {
                "lessThan": "6.5.9",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "6.5.9",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user."
      }
    ],
    "id": "CVE-2026-103263",
    "lastModified": "2026-10-01T20:17:23.097",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103263",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T19:29:31.769581Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T11:17:21.233",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-59"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss
cvss
Red Hat5.9
receipt
Source
Red Hat
Its words
5.9
Read by
field:cvss3_score
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-103263",
  "CWE": "CWE-59",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544519",
  "bugzilla_description": "tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler",
  "cvss3_score": "5.9",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-01T10:42:05Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-103263.json",
  "severity": "moderate"
}
—
Cwe
cwe
GitHub advisoriesCWE-59
receipt
Source
GitHub advisories
Its words
CWE-59
Read by
field:cwes[].cwe_id
Said since
2026-10-02 11:59 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103263",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-59",
      "name": "Improper Link Resolution Before File Access ('Link Following')"
    }
  ],
  "description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
  "ghsa_id": "GHSA-4cjq-6jh9-w2f5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4cjq-6jh9-w2f5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103263"
    }
  ],
  "nvd_published_at": "2026-10-01T11:17:21Z",
  "published_at": "2026-10-01T12:31:17Z",
  "references": [
    "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
    "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
    "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
    "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:18Z",
  "url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Cwe
cwe
Red HatCWE-59
receipt
Source
Red Hat
Its words
CWE-59
Read by
field:CWE
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-103263",
  "CWE": "CWE-59",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544519",
  "bugzilla_description": "tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler",
  "cvss3_score": "5.9",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-01T10:42:05Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-103263.json",
  "severity": "moderate"
}
—
Product
product
NVDtornado
receipt
Source
NVD
Its words
tornado
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:pypi/tornado",
            "product": "tornado",
            "vendor": "tornadoweb",
            "versions": [
              {
                "lessThan": "6.5.9",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "6.5.9",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user."
      }
    ],
    "id": "CVE-2026-103263",
    "lastModified": "2026-10-01T20:17:23.097",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103263",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T19:29:31.769581Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T11:17:21.233",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-59"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
conflict
GitHub advisorieshigh
From 7.0 to 8.9.
receipt
Source
GitHub advisories
Its words
high
Read by
field:severity
Said since
2026-10-02 11:59 UTC
Original
open at the source
What the source handed over
{
  "credits": [],
  "cve_id": "CVE-2026-103263",
  "cvss": {
    "score": 5.9,
    "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.9,
      "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
    },
    "cvss_v4": {
      "score": 8.2,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-59",
      "name": "Improper Link Resolution Before File Access ('Link Following')"
    }
  ],
  "description": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.",
  "ghsa_id": "GHSA-4cjq-6jh9-w2f5",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4cjq-6jh9-w2f5"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-103263"
    }
  ],
  "nvd_published_at": "2026-10-01T11:17:21Z",
  "published_at": "2026-10-01T12:31:17Z",
  "references": [
    "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-103263",
    "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32",
    "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink",
    "https://github.com/advisories/GHSA-4cjq-6jh9-w2f5"
  ],
  "repository_advisory_url": null,
  "severity": "high",
  "source_code_location": "",
  "summary": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...",
  "type": "unreviewed",
  "updated_at": "2026-10-01T12:31:18Z",
  "url": "https://api.github.com/advisories/GHSA-4cjq-6jh9-w2f5",
  "vulnerabilities": [],
  "withdrawn_at": null
}
—
Severity
severity
conflict
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-10-02 12:01 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-103263",
  "CWE": "CWE-59",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2544519",
  "bugzilla_description": "tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler",
  "cvss3_score": "5.9",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-01T10:42:05Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-103263.json",
  "severity": "moderate"
}
medium
Status
status
NVDDeferred
receipt
Source
NVD
Its words
Deferred
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:pypi/tornado",
            "product": "tornado",
            "vendor": "tornadoweb",
            "versions": [
              {
                "lessThan": "6.5.9",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "6.5.9",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user."
      }
    ],
    "id": "CVE-2026-103263",
    "lastModified": "2026-10-01T20:17:23.097",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103263",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T19:29:31.769581Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T11:17:21.233",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-59"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDtornadoweb
receipt
Source
NVD
Its words
tornadoweb
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 06:13 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:pypi/tornado",
            "product": "tornado",
            "vendor": "tornadoweb",
            "versions": [
              {
                "lessThan": "6.5.9",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              },
              {
                "status": "unaffected",
                "version": "6.5.9",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "disclosure@vulncheck.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user."
      }
    ],
    "id": "CVE-2026-103263",
    "lastModified": "2026-10-01T20:17:23.097",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "disclosure@vulncheck.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-103263",
            "options": [
              {
                "exploitation": "poc"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-10-01T19:29:31.769581Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-10-01T11:17:21.233",
    "references": [
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/tornadoweb/tornado/commit/437ab5f76565403b3403438d2e555d11f8128d32"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
      },
      {
        "source": "disclosure@vulncheck.com",
        "url": "https://www.vulncheck.com/advisories/tornado-before-6.5.9-staticfilehandler-path-traversal-via-symlink"
      },
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-c2m8-h5v5-343r"
      }
    ],
    "sourceIdentifier": "disclosure@vulncheck.com",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-59"
          }
        ],
        "source": "disclosure@vulncheck.com",
        "type": "Secondary"
      }
    ]
  }
}
—

vulnerability

tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler
zetlyn/cve-redhat · 2026-10-01
cvss 5.9 cwe CWE-59 severity moderate source
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.
zetlyn/cve-nvd · 2026-10-01
cvss 5.9 product tornado status Deferred vendor tornadoweb source
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...
zetlyn/cve-ghsa · 2026-10-01
cvss 5.9 cwe CWE-59 severity high source