In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 03 Apr 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters. | |
| Weaknesses | CWE-159 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T02:25:57.427Z
Reserved: 2026-04-03T02:25:57.035Z
Link: CVE-2026-35536
No data.
Status : Received
Published: 2026-04-03T04:16:53.550
Modified: 2026-04-03T04:16:53.550
Link: CVE-2026-35536
No data.
OpenCVE Enrichment
No data.
Weaknesses