AZL-105375

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105375.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105375
Upstream
Published
2026-10-01T11:17:21Z
Modified
2026-10-03T14:16:31Z
Summary
CVE-2026-103263 affecting package python-tornado 6.3.3-11
Details

Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows symbolic links inside the static root without confirming the resolved target stays within it. When a symlink pointing outside the static directory exists inside it, unauthenticated attackers can request it to read files such as configuration files, private keys, and application secrets accessible to the process user.

References

Affected packages

Azure Linux:3 / python-tornado

Package

Name
python-tornado
Purl
pkg:rpm/azure-linux/python-tornado

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
6.3.3-11

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105375.json"