CVE-2026-35536

HIGH

Tornado <6.5.5 - Cookie Attribute Injection

Title source: llm
STIX 2.1

Description

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

Scores

CVSS v3 7.2
EPSS 0.0002
EPSS Percentile 4.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-159
Status published
Products (3)
pypi/tornado 0 - 6.5.5PyPI
tornadoweb/Tornado < 6.5.5
tornadoweb/tornado < 6.5.5
Published Apr 03, 2026
Tracked Since Apr 03, 2026