PT-2026-29974 · Tornado+4 · Tornado+4

·

CVE-2026-35536

·

Published

2026-03-11

·

Updated

2026-07-21

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.5.5
Description Prior to version 6.5.5, Tornado is susceptible to cookie attribute injection due to insufficient validation of the domain, path, and samesite arguments when setting cookies using .RequestHandler.set cookie. This could allow for crafted characters to be injected into these attributes.
Recommendations Update to Tornado version 6.5.5 or later.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:13641
ALSA-2026:13670
ALSA-2026:19034
ALSA-2026:19189
BDU:2026-07217
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EM82280
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-35536
ECHO-B644-E810-F4A8
GHSA-78CV-MQJ4-43F7
GHSA-FQWM-6JPJ-5WXC
OESA-2026-1903
PYSEC-2026-2287
RHSA-2026:13641
RHSA-2026:13670
RHSA-2026:19034
RHSA-2026:19189
RHSA-2026:20572
RHSA-2026:20573
RHSA-2026:20577
RHSA-2026:20810
RHSA-2026:24342
USN-8198-1
USN-8198-2

Affected Products

Linuxmint
Red Os
Rocky Linux
Tornado
Ubuntu