Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35536

Опубликовано: 03 апр. 2026
Источник: redhat
CVSS3: 5.4

Описание

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

A flaw was found in Tornado. A remote attacker could exploit this vulnerability by injecting specially crafted characters into the domain, path, and samesite arguments when setting cookies. This could lead to cookie attribute injection, potentially allowing for information disclosure or manipulation of client-side data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-bundleAffected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-operator-rhel9Affected
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/external-secrets-rhel9Affected
Lightspeed Coreansible-automation-platform-26/lightspeed-chatbot-rhel9Not affected
Lightspeed Coreopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
Red Hat Enterprise Linux 8pcsNot affected
Red Hat Enterprise Linux 9pcsNot affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2454716tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
nvd
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

CVSS3: 7.2
debian
4 месяца назад

In Tornado before 6.5.5, cookie attribute injection could occur becaus ...

CVSS3: 7.2
github
4 месяца назад

Tornado has cookie attribute injection via .RequestHandler.set_cookie

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость веб-фреймворка и асинхронной сетевой библиотеки Tornado, связанная с некорректной обработкой специальных элементов, позволяющая нарушителю выполнить произвольный код

5.4 Medium

CVSS3