Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35536

Опубликовано: 03 апр. 2026
Источник: redhat
CVSS3: 5.4

Описание

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the domain, path, and samesite arguments when setting cookies. This could lead to cookie attribute injection, potentially allowing for information disclosure or manipulation of client-side data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-bundleAffected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-rhel9Affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Affected
Lightspeed Coreansible-automation-platform-26/lightspeed-chatbot-rhel9Not affected
Lightspeed Coreopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
Red Hat Enterprise Linux 8pcsNot affected
Red Hat Enterprise Linux 9pcsNot affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2454716tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
5 месяцев назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
nvd
5 месяцев назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
debian
5 месяцев назад

In Tornado before 6.5.5, cookie attribute injection could occur becaus ...

CVSS3: 5.3
redos
4 месяца назад

Уязвимость python-tornado

CVSS3: 7.2
github
5 месяцев назад

Tornado has cookie attribute injection via .RequestHandler.set_cookie

5.4 Medium

CVSS3