In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cookie Attribute Injection in Tornado’s set_cookie | |
| First Time appeared |
Tornadoweb
Tornadoweb tornado |
|
| Vendors & Products |
Tornadoweb
Tornadoweb tornado |
Fri, 03 Apr 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters. | |
| Weaknesses | CWE-159 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T13:12:16.105Z
Reserved: 2026-04-03T02:25:57.035Z
Link: CVE-2026-35536
No data.
Status : Awaiting Analysis
Published: 2026-04-03T04:16:53.550
Modified: 2026-04-03T16:10:23.730
Link: CVE-2026-35536
No data.
OpenCVE Enrichment
Updated: 2026-04-03T09:15:59Z
Weaknesses