CVE-2026-103263 | TornadoWeb Tornado up to 6.5.8 StaticFileHandler path traversal

SecurityVulns

A vulnerability was found in TornadoWeb Tornado up to 6.5.8. It has been declared as problematic. Affected by this issue is the function StaticFileHandler. Executing a manipulation can lead to path traversal.

This vulnerability is registered as CVE-2026-103263. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More