Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fqwm-6jpj-5wxc | Tornado has cookie attribute injection via .RequestHandler.set_cookie |
Ubuntu USN |
USN-8198-1 | Tornado vulnerabilities |
Ubuntu USN |
USN-8198-2 | Tornado vulnerabilities |
Fri, 10 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:* |
Sat, 04 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 04 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cookie Attribute Injection in Tornado’s set_cookie | tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cookie Attribute Injection in Tornado’s set_cookie | |
| First Time appeared |
Tornadoweb
Tornadoweb tornado |
|
| Vendors & Products |
Tornadoweb
Tornadoweb tornado |
Fri, 03 Apr 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters. | |
| Weaknesses | CWE-159 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-03T13:12:16.105Z
Reserved: 2026-04-03T02:25:57.035Z
Link: CVE-2026-35536
Updated: 2026-04-03T13:12:12.583Z
Status : Analyzed
Published: 2026-04-03T04:16:53.550
Modified: 2026-04-10T15:14:22.700
Link: CVE-2026-35536
OpenCVE Enrichment
Updated: 2026-04-13T14:28:00Z
Github GHSA
Ubuntu USN