CVE-2026-35536CWE-159

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked…

High · published April 3, 2026

CVSS v3.1
7.2
EPSS
0%
Percentile
14.6
In the wild
Unconfirmed
What it is

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

The record
Technical detail
CVSS v3.1
7.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00237 · 14.6th percentile
Weakness
CWE-159 · Improper Handling of Invalid Use of Special Elements
Published
2026-04-03T02:25Z
EPSS history
Timeline
  • 03 APR 02:25Z
    In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked…
    cvelistv5