CVE-2026-35536
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cook
CVSS
7.2
High
EPSS
0.2%
p15
KEV
—
Exploit Today
4
0-100
Published: Apr 3, 2026 · Last modified: Jul 24, 2026 · CWE-159
0.2%EPSS · 30 days0.2%
2026-08-072026-09-03
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.