Symlink Attack Affecting tornado package, versions [,6.5.9)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.52% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-TORNADO-20415627
  • published3 Oct 2026
  • disclosed1 Oct 2026
  • creditUnknown

Introduced: 1 Oct 2026

NewCVE-2026-103263  (opens in a new tab)
CWE-59  (opens in a new tab)

How to fix?

Upgrade tornado to version 6.5.9 or higher.

Overview

tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed.

Affected versions of this package are vulnerable to Symlink Attack via StaticFileHandler.validate_absolute_path in tornado/web.py, which uses os.path.abspath to validate that a requested path remains within the configured static root directory but does not resolve symlinks. An attacker can place or exploit a symlink inside the static directory that points to an arbitrary location on the filesystem, causing StaticFileHandler to serve files outside the intended root - both symlinked files and symlinked directories are affected. The fix introduces a secondary check using os.path.realpath against a configurable allowed_symlink_directory boundary.

Note: This is only exploitable when a symlink exists inside the configured static directory pointing to a location outside it.

CVSS Base Scores

version 4.0
version 3.1