cbcvebase.
CVE-2026-35536
published 2026-04-03

CVE-2026-35536: In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked…

PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.24%
14.8th percentile
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianpython-tornado< python-tornado 6.1.0-1+deb11u4 (bullseye)python-tornado 6.1.0-1+deb11u4 (bullseye)
tornadowebtornado< 6.5.56.5.5
tornadowebtornado>= 0 < 6.5.56.5.5
ubuntupython-tornado

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_ubuntu8.7HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.