CVE-2026-35536: High severity tornadoweb tornado vulnerability
Published Apr 3, 2026
·Updated
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.setcookie were not checked for crafted characters.
Other sources
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.setcookie were not checked for crafted characters.
— GitHub
Affected Software
4 affected componentsFixes available
pip/tornado<6.5.5
6.5.5
tornadoweb tornado<6.5.5
IBM Db2 Genius Hub<=1.1, 1.1.1, 1.1.2
IBM Agentics<=1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/tornadoto a version that resolves this vulnerability.Fixed in 6.5.5
Event History
Apr 3, 2026
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·04:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
Affected Software
Advisory Published
via GitHub·06:31 AM
Data Sourced
via GitHub·06:31 AM
DescriptionSeverityWeaknessAffected Software
Jul 13, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software