
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35536 is a cookie attribute injection vulnerability in the Tornado Python web framework affecting all versions before 6.5.5. The flaw exists in RequestHandler.set_cookie, where the domain, path, and samesite arguments were not validated for crafted or illegal characters (such as semicolons), enabling injection of attacker-controlled cookie attributes. It was disclosed on April 3, 2026, with the upstream fix released on March 10, 2026 in Tornado 6.5.5. The CVSS v3.1 base score is 5.3 (Medium) per NVD, though the GitHub Advisory Database rates it 7.2 (High) with a changed scope (Github Advisory, Tornado Advisory).
The root cause is insufficient input validation (CWE-159: Improper Handling of Invalid Use of Special Elements; CWE-88: Improper Neutralization of Argument Delimiters) in Tornado's RequestHandler.set_cookie method. Specifically, semicolons and other special characters were permitted in the domain, path, and samesite cookie attribute arguments, allowing an attacker who can influence these values to inject additional, attacker-controlled cookie attributes into the Set-Cookie HTTP response header. Exploitation requires that attacker-controlled input reaches one of these cookie attribute parameters — a condition that may arise in applications that dynamically construct cookie attributes from user-supplied data. The vulnerability was reported by Dhiral Vyas of Praetorian (Tornado Release, Github Advisory).
Successful exploitation allows an attacker to manipulate cookie attributes in HTTP responses, potentially enabling session fixation attacks, bypassing SameSite or Secure cookie security policies, or facilitating session hijacking by steering cookies to attacker-controlled domains. The confidentiality and integrity of session data are at risk, though availability is not directly affected. The scope of impact can extend beyond the vulnerable component if injected cookie attributes affect browser behavior across origins (Github Advisory, Tornado Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.019% (5th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires that attacker-controlled input reaches the domain, path, or samesite parameters of set_cookie, which limits the attack surface to applications with specific coding patterns.
domain, path, or samesite arguments of RequestHandler.set_cookie.example.com; Secure; HttpOnly for the domain argument, or ; SameSite=None; Secure for the samesite argument.set_cookie with the attacker-influenced value — for example, via a URL parameter, form field, or HTTP header that the application reflects into a cookie attribute.Set-Cookie header with the injected attributes, e.g., Set-Cookie: session=abc; Domain=example.com; Secure; HttpOnly — attributes the attacker appended.SameSite protections to enable CSRF, or redirect cookie scope to a broader or attacker-controlled domain (Github Advisory, Tornado Advisory).Set-Cookie headers with unexpected or duplicate cookie attributes (e.g., multiple Domain=, SameSite=, or Path= directives in a single Set-Cookie header); Set-Cookie headers containing semicolons within attribute values.Set-Cookie header values in response logs.Secure/HttpOnly flags, or SameSite attributes inconsistent with application configuration.Upgrade Tornado to version 6.5.5 or later, which validates the domain, path, and samesite arguments to RequestHandler.set_cookie for illegal characters (Tornado Release). As a short-term workaround where upgrading is not immediately possible, applications should sanitize or strictly validate any user-controlled input before passing it to set_cookie cookie attribute arguments, rejecting inputs containing semicolons or other special characters. Red Hat has issued multiple errata addressing this issue across RHEL 7, 9, and 10 (RHSA-2026:13641, RHSA-2026:13670, RHSA-2026:19034, RHSA-2026:19189, RHSA-2026:20572, RHSA-2026:20573, RHSA-2026:20577, RHSA-2026:20810, RHSA-2026:24342), and Ubuntu has issued USN-8198-1 and USN-8198-2 (Red Hat Bugzilla).
The vulnerability was reported to the Tornado project by Dhiral Vyas of Praetorian security firm, and the fix was credited in the official release notes (Tornado Release). Red Hat triaged the issue as medium severity and issued multiple errata across several RHEL versions, reflecting broad downstream impact on enterprise Linux distributions (Red Hat Bugzilla). IBM also issued advisories for affected products including IBM API Connect and Cloudera Data Platform Private Cloud Base. No significant social media controversy or notable researcher commentary beyond standard disclosure activity has been observed.
Fix availability across major Linux distributions and their releases.
bookworm
python-tornado
sid
python-tornado: 6.5.5-1
trixie
python-tornado
bionic (esm-apps)
python-tornado: 4.5.3-1ubuntu0.2+esm3
devel
python-tornado
focal (esm-apps)
python-tornado: 6.0.3+really5.1.1-3ubuntu0.1~esm5
jammy
python-tornado
jammy (esm-apps)
python-tornado: 6.1.0-3ubuntu0.1~esm5
noble
python-tornado: 6.4.0-1ubuntu0.5
questing
python-tornado: 6.4.2-3ubuntu0.3
resolute
python-tornado: 6.5.4-0.1ubuntu0.1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."