PT-2026-29974 · Tornado+4 · Tornado+4
Dhiral2908
·
Published
2026-04-03
·
Updated
2026-05-19
·
CVE-2026-35536
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tornado versions prior to 6.5.5
Description
Prior to version 6.5.5, Tornado is susceptible to cookie attribute injection due to insufficient validation of the domain, path, and samesite arguments when setting cookies using
.RequestHandler.set cookie. This could allow for crafted characters to be injected into these attributes.Recommendations
Update to Tornado version 6.5.5 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Red Os
Rocky Linux
Tornado
Ubuntu