CVE-2026-103263 - Tornado before 6.5.9 StaticFileHandler Path Traversal via Symlink
CVE ID :CVE-2026-103263 Published : Oct. 1, 2026, 11:17 a.m. | 2 hours ago Description :Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink...