Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35536

Опубликовано: 03 апр. 2026
Источник: debian

Описание

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-tornadofixed6.5.5-1package
python-tornadono-dsatrixiepackage

Примечания

  • https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7

  • Fixed by: https://github.com/tornadoweb/tornado/commit/24a2d96ea115f663b223887deb0060f13974c104 (v6.5.5)

Связанные уязвимости

CVSS3: 7.2
ubuntu
5 месяцев назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 5.4
redhat
5 месяцев назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
nvd
5 месяцев назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 5.3
redos
4 месяца назад

Уязвимость python-tornado

CVSS3: 7.2
github
5 месяцев назад

Tornado has cookie attribute injection via .RequestHandler.set_cookie