Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91991

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.

A flaw was found in Tornado. An attacker can bypass security validation in the set_cookie function by using capitalized or legacy keyword arguments. This allows the attacker to inject arbitrary cookie attributes, such as Domain or SameSite, and modify cookie security settings. The consequence is the potential to manipulate cookie behavior, which could lead to unintended security impacts.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Out of support scope
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cpu-rhel9Fix deferred
Lightspeed Corelightspeed-core/rag-tool-cuda-12.9-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Not affected
Red Hat Enterprise Linux 10python-tornadoNot affected
Red Hat Enterprise Linux 10rhel10/keylime-registrarNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-915
https://bugzilla.redhat.com/show_bug.cgi?id=2533964tornado: Tornado: Cookie attribute injection via capitalized keyword arguments

EPSS

Процентиль: 13%
0.00219
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
5 дней назад

(Tornado before 6.5.8 contains an incomplete fix for cookie attribute i ...)

CVSS3: 5.4
nvd
5 дней назад

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.

CVSS3: 5.4
debian
5 дней назад

Tornado before 6.5.8 contains an incomplete fix for cookie attribute i ...

CVSS3: 5.4
github
5 дней назад

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.

EPSS

Процентиль: 13%
0.00219
Низкий

5.4 Medium

CVSS3

Уязвимость CVE-2026-91991