PT-2026-29974 · Tornado+4 · Tornado+4

Dhiral2908

·

Published

2026-04-03

·

Updated

2026-05-19

·

CVE-2026-35536

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.5.5
Description Prior to version 6.5.5, Tornado is susceptible to cookie attribute injection due to insufficient validation of the domain, path, and samesite arguments when setting cookies using .RequestHandler.set cookie. This could allow for crafted characters to be injected into these attributes.
Recommendations Update to Tornado version 6.5.5 or later.

Fix

Weakness Enumeration

Related Identifiers

ALSA-2026:13641
ALSA-2026:13670
ALSA-2026:19034
ALSA-2026:19189
BDU:2026-07217
CVE-2026-35536
ECHO-B644-E810-F4A8
GHSA-FQWM-6JPJ-5WXC
OESA-2026-1903
RHSA-2026:13641
RHSA-2026:13670
USN-8198-1
USN-8198-2

Affected Products

Linuxmint
Red Os
Rocky Linux
Tornado
Ubuntu