CVE-2026-35536: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-35536 is a cookie attribute injection vulnerability in the Tornado Python web framework affecting all versions before 6.5.5. The flaw exists in RequestHandler.set_cookie, where the domain, path, and samesite arguments were not validated for crafted or illegal characters (such as semicolons), enabling injection of attacker-controlled cookie attributes. It was disclosed on April 3, 2026, with the upstream fix released on March 10, 2026 in Tornado 6.5.5. The CVSS v3.1 base score is 5.3 (Medium) per NVD, though the GitHub Advisory Database rates it 7.2 (High) with a changed scope (Github Advisory, Tornado Advisory).

Technical details

The root cause is insufficient input validation (CWE-159: Improper Handling of Invalid Use of Special Elements; CWE-88: Improper Neutralization of Argument Delimiters) in Tornado's RequestHandler.set_cookie method. Specifically, semicolons and other special characters were permitted in the domain, path, and samesite cookie attribute arguments, allowing an attacker who can influence these values to inject additional, attacker-controlled cookie attributes into the Set-Cookie HTTP response header. Exploitation requires that attacker-controlled input reaches one of these cookie attribute parameters — a condition that may arise in applications that dynamically construct cookie attributes from user-supplied data. The vulnerability was reported by Dhiral Vyas of Praetorian (Tornado Release, Github Advisory).

Impact

Successful exploitation allows an attacker to manipulate cookie attributes in HTTP responses, potentially enabling session fixation attacks, bypassing SameSite or Secure cookie security policies, or facilitating session hijacking by steering cookies to attacker-controlled domains. The confidentiality and integrity of session data are at risk, though availability is not directly affected. The scope of impact can extend beyond the vulnerable component if injected cookie attributes affect browser behavior across origins (Github Advisory, Tornado Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.019% (5th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that attacker-controlled input reaches the domain, path, or samesite parameters of set_cookie, which limits the attack surface to applications with specific coding patterns.

Exploitation steps

  1. Identify a vulnerable target: Find a web application running Tornado versions prior to 6.5.5 that dynamically passes user-controlled or externally influenced values to the domain, path, or samesite arguments of RequestHandler.set_cookie.
  2. Craft a malicious input: Prepare a payload containing a semicolon followed by an injected cookie attribute, for example: example.com; Secure; HttpOnly for the domain argument, or ; SameSite=None; Secure for the samesite argument.
  3. Trigger cookie setting: Submit a request to the application that causes the server to call set_cookie with the attacker-influenced value — for example, via a URL parameter, form field, or HTTP header that the application reflects into a cookie attribute.
  4. Observe injected Set-Cookie header: The server's HTTP response will contain a Set-Cookie header with the injected attributes, e.g., Set-Cookie: session=abc; Domain=example.com; Secure; HttpOnly — attributes the attacker appended.
  5. Leverage the injected attribute: Use the injected attribute to perform session fixation (by forcing a known session ID), bypass SameSite protections to enable CSRF, or redirect cookie scope to a broader or attacker-controlled domain (Github Advisory, Tornado Advisory).

Indicators of compromise

  • Network: HTTP responses from the Tornado application containing Set-Cookie headers with unexpected or duplicate cookie attributes (e.g., multiple Domain=, SameSite=, or Path= directives in a single Set-Cookie header); Set-Cookie headers containing semicolons within attribute values.
  • Logs: Application or web server access logs showing requests with unusual characters (semicolons, newlines) in parameters that are reflected into cookie-setting logic; unexpected Set-Cookie header values in response logs.
  • Application Behavior: Cookies being set with broader-than-expected domain scope, missing or overridden Secure/HttpOnly flags, or SameSite attributes inconsistent with application configuration.

Mitigation and workarounds

Upgrade Tornado to version 6.5.5 or later, which validates the domain, path, and samesite arguments to RequestHandler.set_cookie for illegal characters (Tornado Release). As a short-term workaround where upgrading is not immediately possible, applications should sanitize or strictly validate any user-controlled input before passing it to set_cookie cookie attribute arguments, rejecting inputs containing semicolons or other special characters. Red Hat has issued multiple errata addressing this issue across RHEL 7, 9, and 10 (RHSA-2026:13641, RHSA-2026:13670, RHSA-2026:19034, RHSA-2026:19189, RHSA-2026:20572, RHSA-2026:20573, RHSA-2026:20577, RHSA-2026:20810, RHSA-2026:24342), and Ubuntu has issued USN-8198-1 and USN-8198-2 (Red Hat Bugzilla).

Community reactions

The vulnerability was reported to the Tornado project by Dhiral Vyas of Praetorian security firm, and the fix was credited in the official release notes (Tornado Release). Red Hat triaged the issue as medium severity and issued multiple errata across several RHEL versions, reflecting broad downstream impact on enterprise Linux distributions (Red Hat Bugzilla). IBM also issued advisories for affected products including IBM API Connect and Cloudera Data Platform Private Cloud Base. No significant social media controversy or notable researcher commentary beyond standard disclosure activity has been observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

python-tornado

Affected

sid

python-tornado: 6.5.5-1

Fixed

trixie

python-tornado

Affected

Ubuntu

Fixed

bionic (esm-apps)

python-tornado: 4.5.3-1ubuntu0.2+esm3

Fixed

devel

python-tornado

Not Affected

focal (esm-apps)

python-tornado: 6.0.3+really5.1.1-3ubuntu0.1~esm5

Fixed

jammy

python-tornado

Affected

jammy (esm-apps)

python-tornado: 6.1.0-3ubuntu0.1~esm5

Fixed

noble

python-tornado: 6.4.0-1ubuntu0.5

Fixed

questing

python-tornado: 6.4.2-3ubuntu0.3

Fixed

resolute

python-tornado: 6.5.4-0.1ubuntu0.1

Fixed

RHEL / CentOS

Fixed

OpenShift

Not Affected

RHEL 8

Not Affected

RHEL 9

:appstream:python-tornado-0:6.4.2-1.el9_2.2.src

Fixed

RHEL 10

python-tornado-0:6.4.2-1.el10_0.2.src

Fixed

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management