CVE-2026-35536: High severity tornadoweb tornado vulnerability
Published Apr 3, 2026
·Updated
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.setcookie were not checked for crafted characters.
Other sources
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.setcookie were not checked for crafted characters.
— GitHub
Affected Software
2 affected componentsFixes available
pip/tornado<6.5.5
6.5.5
tornadoweb tornado<6.5.5
Event History
Apr 3, 2026
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·04:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
Affected Software
Advisory Published
via GitHub·06:31 AM
Data Sourced
via GitHub·06:31 AM
DescriptionSeverityWeaknessAffected Software