CVE-2026-35536
published 2026-04-03CVE-2026-35536: In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.24%
14.8th percentile
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-tornado | < python-tornado 6.1.0-1+deb11u4 (bullseye) | python-tornado 6.1.0-1+deb11u4 (bullseye) |
| tornadoweb | tornado | < 6.5.5 | 6.5.5 |
| tornadoweb | tornado | >= 0 < 6.5.5 | 6.5.5 |
| ubuntu | python-tornado | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_ubuntu8.7HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Tornado has cookie attribute injection via .RequestHandler.set_cookie
osv·2026-04-03
CVE-2026-35536 [HIGH] Tornado has cookie attribute injection via .RequestHandler.set_cookie
Tornado has cookie attribute injection via .RequestHandler.set_cookie
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to `.RequestHandler.set_cookie` were not checked for crafted characters.
OSV
CVE-2026-35536: In Tornado before 6
osv·2026-04-03·CVSS 5.3
CVE-2026-35536 [MEDIUM] CVE-2026-35536: In Tornado before 6
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
GHSA
Tornado has cookie attribute injection via .RequestHandler.set_cookie
ghsa·2026-04-03
CVE-2026-35536 [HIGH] CWE-159 Tornado has cookie attribute injection via .RequestHandler.set_cookie
Tornado has cookie attribute injection via .RequestHandler.set_cookie
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to `.RequestHandler.set_cookie` were not checked for crafted characters.
Ubuntu
Tornado vulnerabilities
vendor_ubuntu·2026-04-28·CVSS 8.7
CVE-2026-35536 [HIGH] Tornado vulnerabilities
Title: Tornado vulnerabilities
Summary: Several security issues were fixed in Tornado.
USN-8198-1 fixed vulnerabilities in Tornado. This update provides the
corresponding updates for Ubuntu 26.04 LTS.
Original advisory details:
It was discovered that Tornado incorrectly handled parsing of large
multipart request bodies. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-31958)
It was discovered that Tornado did not properly validate characters in
cookie values. An attacker could possibly use this issue to inject
arbitrary cookie attributes. (CVE-2026-35536)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Tornado vulnerabilities
vendor_ubuntu·2026-04-22·CVSS 8.7
CVE-2026-31958 [HIGH] Tornado vulnerabilities
Title: Tornado vulnerabilities
Summary: Several security issues were fixed in Tornado.
It was discovered that Tornado incorrectly handled parsing of large
multipart request bodies. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-31958)
It was discovered that Tornado did not properly validate characters in
cookie values. An attacker could possibly use this issue to inject
arbitrary cookie attributes. (CVE-2026-35536)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
vendor_redhat·2026-04-03·CVSS 7.2
CVE-2026-35536 [HIGH] CWE-88 tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the `domain`, `path`, and `samesite` arguments when setting cookies. This could lead to cookie attribute injection, potentially allowing for information disclosure or manipulation of client-side data.
Package: redhat-user-workloads/bitwarden-sdk-server-1-0 (External Secrets Operator for Red Hat OpenShift) - Affected
Package: redhat-user-workloads/external-secrets-1-0 (External Secrets Operato
Debian
CVE-2026-35536: python-tornado - In Tornado before 6.5.5, cookie attribute injection could occur because the doma...
vendor_debian·2026·CVSS 7.2
CVE-2026-35536 [HIGH] CVE-2026-35536: python-tornado - In Tornado before 6.5.5, cookie attribute injection could occur because the doma...
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Scope: local
bookworm: open
bullseye: resolved (fixed in 6.1.0-1+deb11u4)
forky: resolved (fixed in 6.5.5-1)
sid: resolved (fixed in 6.5.5-1)
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-28363 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.9
CVE-2026-28363 [CRITICAL] CVE-2026-28363 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-28363 :
MinimOS vulnerability analysis and mitigation
In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as --compress-prog) in allowlist mode, leading to approval-free execution paths that were intended to require approval. Only an exact string such as --compress-program was denied.
Source : NVD
## 8.8
Score
Published February 27, 2026
Severity HIGH
CNA Score 9.9
Affected Technologies
MinimOS
OpenClaw (formerly Moltbot or Clawdbot)
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 12.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
openclaw
Sources
NVD
npm Severity CRITI
Wiz
CVE-2026-1519 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-1519 [HIGH] CVE-2026-1519 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1519 :
MinimOS vulnerability analysis and mitigation
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries ).
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
MinimOS
Linux Debian
Has Publi
Wiz
CVE-2026-3591 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.6
CVE-2026-3591 [HIGH] CVE-2026-3591 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3591 :
MinimOS vulnerability analysis and mitigation
named
Source : NVD
## 5.4
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
MinimOS
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
bind9.16-libs
bind9.16-license
Sources
NVD
Alpine 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 26, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Mar 26, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Mar 26, 2026
Echo Severity MEDIUM No Fix Added at: Mar 26, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 29, 2026
Red Hat 6, 7, 8, 9, 10 Seve
Wiz
CVE-2026-22822 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.3
CVE-2026-22822 [CRITICAL] CVE-2026-22822 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22822 :
MinimOS vulnerability analysis and mitigation
getSecretKey
getSecretKey
Source : NVD
## 9.3
Score
Published January 21, 2026
Severity CRITICAL
CNA Score 9.3
Affected Technologies
MinimOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
external-secrets-operator
github.com/external-secrets/external-secrets
Sources
NVD
GoLang Severity CRITICAL Has Fix Added at: Jan 21, 2026
MinimOS Severity HIGH Has Fix Added at: Jan 22, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
## Related MinimOS vul
Wiz
CVE-2026-34742 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.6
CVE-2026-34742 [HIGH] CVE-2026-34742 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-34742 :
MinimOS vulnerability analysis and mitigation
The Go MCP SDK used Go's standard encoding/json. Prior to version 1.4.0, the Model Context Protocol (MCP) Go SDK does not enable DNS rebinding protection by default for HTTP-based servers. When an HTTP-based MCP server is run on localhost without authentication with StreamableHTTPHandler or SSEHandler, a malicious website could exploit DNS rebinding to bypass same-origin policy restrictions and send requests to the local MCP server. This could allow an attacker to invoke tools or access resources exposed by the MCP server on behalf of the user in those limited circumstances. This issue has been patched in version 1.4.0.
Source : NVD
## 7.6
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.6
Affected Technolo
Wiz
CVE-2026-3119 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2026-3119 [MEDIUM] CVE-2026-3119 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3119 :
MinimOS vulnerability analysis and mitigation
named
named
Source : NVD
## 6.5
Score
Published March 25, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
MinimOS
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
bind9.18-utils
bind-dnssec-utils
Sources
NVD
Alpine 3.22, 3.23, edge Severity MEDIUM Has Fix Added at: Mar 26, 2026
Debian 11, 12 Severity MEDIUM No Fix Added at: Mar 26, 2026
Debian 13, 14 Severity MEDIUM Has Fix Added at: Mar 26, 2026
Echo Severity MEDIUM No Fix Added at: Mar 26, 2026
MinimOS Severity MEDIUM Has Fix Added at: Mar 29, 2026
Red Hat 6, 7, 8,
Wiz
CVE-2026-3104 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-3104 [HIGH] CVE-2026-3104 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3104 :
MinimOS vulnerability analysis and mitigation
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain.
This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Source : NVD
## 7.5
Score
Published March 25, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
MinimOS
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 18.4
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
bind9-next-libs
bind
Sources
NVD
Alpine 3.22, 3.23, edge
Wiz
CVE-2026-35536 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.2
CVE-2026-35536 [HIGH] CVE-2026-35536 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-35536 :
Python vulnerability analysis and mitigation
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Source : NVD
## 7.2
Score
Published April 3, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
Python
MinimOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
python-tornado
tornado
Sources
NVD
Debian 11, 14 Severity HIGH Has Fix Added at: Apr 03, 2026
Debian 12, 13 Severity HIGH No Fix Added at: Apr 03, 2026
Echo Severity HIGH No Fix Added at: Apr 05, 202
Bugzilla
CVE-2026-35536 python-tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments [fedora-all]
bugzilla·2026-04-10·CVSS 7.2
CVE-2026-35536 [HIGH] CVE-2026-35536 python-tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments [fedora-all]
CVE-2026-35536 python-tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-35536 python-tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments [epel-all]
bugzilla·2026-04-10·CVSS 7.2
CVE-2026-35536 [HIGH] CVE-2026-35536 python-tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments [epel-all]
CVE-2026-35536 python-tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-35536 tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
bugzilla·2026-04-03·CVSS 7.2
CVE-2026-35536 [HIGH] CVE-2026-35536 tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
CVE-2026-35536 tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
2026-04-03
Published