---
id: CVE-2026-35536
title: >-
  tornado: Tornado: Cookie attribute injection due to improper handling of
  cookie arguments (CVE-2026-35536)
summary: >-
  A flaw was found in Tornado. A remote attacker could exploit this
  vulnerability by injecting specially crafted characters into the `domain`,
  `path`, and `samesite` arguments when setting cookies. This could lead to
  cookie attribute injecti…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'
cvssSource: vendor
cwe: CWE-88
vendor: Red Hat
product: Red Hat OpenShift AI 2.25
affected:
  - external_secrets_operator_for_red_hat_openshift
  - openshift_lightspeed
  - enterprise_linux_ai_rhel_ai 3
  - openshift_container_platform 4
  - enterprise_linux_server_optional_v_7_els
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - openshift_ai 2.25
  - openshift_ai 3.3
patched:
  - enterprise_linux_server_optional_v_7_els
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_e4s_v_9_2
  - enterprise_linux_appstream_eus_v_9_4
  - enterprise_linux_appstream_eus_v_9_6
  - enterprise_linux_appstream_v_9
  - openshift_ai 2.25
  - openshift_ai 3.3
published: '2026-04-03'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:32:41+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35536.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35536.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-35536'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2454716'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-35536'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-35536'
  - url: 'https://github.com/tornadoweb/tornado/releases/tag/v6.5.5'
  - url: >-
      https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7
  - url: 'https://access.redhat.com/errata/RHSA-2026:24342'
  - url: 'https://access.redhat.com/errata/RHSA-2026:20577'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13641'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19034'
  - url: 'https://access.redhat.com/errata/RHSA-2026:20573'
  - url: 'https://access.redhat.com/errata/RHSA-2026:20810'
  - url: 'https://access.redhat.com/errata/RHSA-2026:20572'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13670'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19189'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65126'
  - url: 'https://access.redhat.com/errata/RHSA-2026:37275'
  - url: 'https://github.com/tornadoweb/tornado'
  - url: >-
      https://github.com/tornadoweb/tornado/commit/24a2d96ea115f663b223887deb0060f13974c104
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00242
epssPercentile: 0.15647
aliases:
  - GHSA-fqwm-6jpj-5wxc
  - GHSA-78cv-mqj4-43f7
  - PYSEC-2026-2287
ecosystem: pip
scores:
  vendor: 5.4
  osv: 7.2
ingestedAt: '2026-07-08T18:25:46.808Z'
---

## Overview

A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the `domain`, `path`, and `samesite` arguments when setting cookies. This could lead to cookie attribute injection, potentially allowing for information disclosure or manipulation of client-side data.

## Vendor advisories

- **RHSA-2026:24342** · Red Hat · fixed in: Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24342)
- **RHSA-2026:20577** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20577)
- **RHSA-2026:13641** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:13641)
- **RHSA-2026:19034** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19034)
- **RHSA-2026:20573** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20573)
- **RHSA-2026:20810** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.4) · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20810)
- **RHSA-2026:20572** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:20572)
- **RHSA-2026:13670** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-05-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:13670)
- **RHSA-2026:19189** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19189)
- **RHSA-2026:65126** · Red Hat · fixed in: Red Hat OpenShift AI 2.25 · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:65126)
- **RHSA-2026:37275** · Red Hat · fixed in: Red Hat OpenShift AI 3.3 · released 2026-07-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:37275)
- **Red Hat VEX** · Moderate · affected: External Secrets Operator for Red Hat OpenShift, OpenShift Lightspeed, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Container Platform 4 · no fix planned: External Secrets Operator for Red Hat OpenShift, OpenShift Lightspeed, Red Hat Enterprise Linux AI (RHEL AI) 3 · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35536.json)

**tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments** — rated Moderate by Red Hat. Released 2026-04-03, updated 2026-09-18.

Affected:

- External Secrets Operator for Red Hat OpenShift
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift Container Platform 4

Fixed:

- Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Red Hat Enterprise Linux AppStream (v. 10)
- Red Hat Enterprise Linux AppStream E4S (v.9.2)
- Red Hat Enterprise Linux AppStream EUS (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.6)
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.3

No fix planned:

- External Secrets Operator for Red Hat OpenShift
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3

Not affected:

- Red Hat OpenShift AI 2.25
- Red Hat OpenShift AI 3.3
- Lightspeed Core
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Container Platform 4

## Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:24342
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:20577
For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2026:13641

## Package advisory (CVE-2026-35536)

Affected packages:

- `tornado < 6.5.5`

Patched in:

- `tornado 6.5.5`

Source: https://osv.dev/vulnerability/GHSA-fqwm-6jpj-5wxc
