Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-103263

Опубликовано: 01 окт. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.

A flaw was found in Tornado. The StaticFileHandler fails to verify that symbolic links (shortcuts pointing to other files) located within the static root directory resolve within that directory. An unauthenticated remote attacker can exploit this path traversal vulnerability by requesting a path associated with a link pointing outside the intended folder. This can result in unauthorized information disclosure, allowing attackers to access sensitive files on the host filesystem such as configuration files, private keys, and application credentials.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Out of support scope
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Fix deferred
Red Hat Enterprise Linux 10python-tornadoFix deferred
Red Hat Enterprise Linux 10rhel10/keylime-registrarFix deferred
Red Hat Enterprise Linux 10rhel10/keylime-verifierFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2544519tornado: Tornado: Information disclosure via symlink path traversal in StaticFileHandler

EPSS

Процентиль: 42%
0.00522
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
8 дней назад

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.

CVSS3: 5.9
nvd
8 дней назад

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.

CVSS3: 5.9
debian
8 дней назад

Tornado before 6.5.9 contains a path traversal vulnerability in Static ...

CVSS3: 5.9
github
8 дней назад

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.

CVSS3: 7.5
fstec
26 дней назад

Уязвимость методов get_absolute_path() и validate_absolute_path() асинхронной сетевой библиотеки Tornado, позволяющая нарушителю читать произвольные файлы

EPSS

Процентиль: 42%
0.00522
Низкий

5.9 Medium

CVSS3