---
id: CVE-2026-91991
title: >-
  Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection
  that allows attackers to inject arbitrary cookie attributes by passing
  capitalized or legacy keyword arguments to set_cookie
summary: >-
  Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection
  that allows attackers to inject arbitrary cookie attributes by passing
  capitalized or legacy keyword arguments to set_cookie. Attackers can embed
  semicolon-de…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-113
  - CWE-915
vendor: tornadoweb
product: tornado
affected:
  - tornado >= 6.5.5 < 6.5.8
patched:
  - tornado 6.5.8
published: '2026-09-15'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T20:17:39.740'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91991'
references:
  - url: >-
      https://github.com/tornadoweb/tornado/security/advisories/GHSA-wwv5-g3v4-889x
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/tornado-before-6.5.8-cookie-attribute-injection-via-capitalized-kwargs
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/tornadoweb/tornado/security/advisories/GHSA-wwv5-g3v4-889x
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/tornadoweb/tornado/pull/3704'
  - url: 'https://github.com/tornadoweb/tornado/pull/3706'
  - url: >-
      https://github.com/tornadoweb/tornado/commit/6ef836e43e1278530041376adb32504daa977b91
  - url: >-
      https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7
  - url: 'https://github.com/tornadoweb/tornado'
  - url: 'https://github.com/tornadoweb/tornado/releases/tag/v6.5.8'
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91991.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-91991'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2533964'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-91991'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91991'
tags:
  - nvd
  - cve.org
  - osv
  - pip
  - csaf
  - vex
  - red-hat
  - exploit-available
epss: 0.00277
epssPercentile: 0.18017
aliases:
  - GHSA-wwv5-g3v4-889x
ecosystem: pip
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-21T19:14:08.258516Z'
ingestedAt: '2026-09-15T15:39:12.907Z'
---

## Overview

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-91991)

Affected packages:

- `tornado >= 6.5.5, < 6.5.8`

Patched in:

- `tornado 6.5.8`

Source: https://osv.dev/vulnerability/GHSA-wwv5-g3v4-889x

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Container Platform 4 · no fix planned: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-91991.json)
