Tornado 6.5.9 之前的版本在 中存在一个路径遍历漏洞。该组件在处理静态文件时,会跟随位于静态根目录内的符号链接(symlink),但未验证解析后的目标路径是否仍保留在静态根目录内。如果静态目录内部存在指向该目录外部的符号链接,未经身份验证的攻击者即可通过请求这些符号链接来读取进程用户可访问的文件,例如配置文件、私钥以及应用程序密钥等敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tornadoweb | tornado | 0 ~ 6.5.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-103262 | 7.5 HIGH | Tornado before 6.5.9 Denial of Service via CurlAsyncHTTPClient |
| CVE-2026-103261 | 5.3 MEDIUM | Tornado before 6.5.9 Denial of Service via Query String |
No comments yet