Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07217

Опубликовано: 03 апр. 2026
Источник: fstec
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Уязвимость веб-фреймворка и асинхронной сетевой библиотеки Tornado, связана с некорректной обработкой специальных элементов. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, выполнить произвольный код

Вендор

Red Hat Inc.
ООО «Ред Софт»
FriendFeed

Наименование ПО

Red Hat Enterprise Linux
РЕД ОС
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux AI
Red Hat OpenShift Lightspeed
External Secrets Operator for Red Hat OpenShift
Lightspeed Core
Red Hat OpenShift AI
Tornado

Версия ПО

7 (Red Hat Enterprise Linux)
8 (Red Hat Enterprise Linux)
7.3 (РЕД ОС)
4 (Red Hat OpenShift Container Platform)
9 (Red Hat Enterprise Linux)
- (Red Hat Enterprise Linux AI)
- (Red Hat OpenShift Lightspeed)
10 (Red Hat Enterprise Linux)
8.0 (РЕД ОС)
- (External Secrets Operator for Red Hat OpenShift)
- (Lightspeed Core)
- (Red Hat OpenShift AI)
до 6.5.5 (Tornado)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 7
Red Hat Inc. Red Hat Enterprise Linux 8
ООО «Ред Софт» РЕД ОС 7.3
Red Hat Inc. Red Hat Enterprise Linux 9
Red Hat Inc. Red Hat Enterprise Linux AI -
Red Hat Inc. Red Hat Enterprise Linux 10
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 5)
Средний уровень опасности (базовая оценка CVSS 3.1 составляет 5,3)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для Tornado:
https://github.com/tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7
Для РедОС:
https://redos.red-soft.ru/search/?iblock_id=&q=CVE-2026-35536
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-35536

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 15%
0.00237
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
redos
3 месяца назад

Уязвимость python-tornado

CVSS3: 7.2
ubuntu
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 5.4
redhat
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
nvd
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
debian
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur becaus ...

EPSS

Процентиль: 15%
0.00237
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2