CVE-2026-35536
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cook
CVSS
7.2
Alto
EPSS
0.2%
p15
KEV
—
Exploit Today
4
0-100
Publicado: 3 abr 2026 · Última mod.: 24 jul 2026 · CWE-159
0.2%EPSS · 30 días0.2%
2026-08-072026-09-04
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.