Количество 14
Количество 14
BDU:2026-07217
Уязвимость веб-фреймворка и асинхронной сетевой библиотеки Tornado, связанная с некорректной обработкой специальных элементов, позволяющая нарушителю выполнить произвольный код
ROS-20260512-73-0012
Уязвимость python-tornado
CVE-2026-35536
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
CVE-2026-35536
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
CVE-2026-35536
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
CVE-2026-35536
In Tornado before 6.5.5, cookie attribute injection could occur becaus ...
GHSA-fqwm-6jpj-5wxc
Tornado has cookie attribute injection via .RequestHandler.set_cookie
RLSA-2026:19189
Moderate: python-tornado security update
RLSA-2026:19034
Moderate: python-tornado security update
RLSA-2026:13670
Moderate: python-tornado security update
RLSA-2026:13641
Moderate: python-tornado security update
ELSA-2026-19189
ELSA-2026-19189: python-tornado security update (MODERATE)
ELSA-2026-13670
ELSA-2026-13670: python-tornado security update (MODERATE)
ELSA-2026-13641
ELSA-2026-13641: python-tornado security update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-07217 Уязвимость веб-фреймворка и асинхронной сетевой библиотеки Tornado, связанная с некорректной обработкой специальных элементов, позволяющая нарушителю выполнить произвольный код | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
ROS-20260512-73-0012 Уязвимость python-tornado | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-35536 In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters. | CVSS3: 7.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-35536 In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters. | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
CVE-2026-35536 In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters. | CVSS3: 7.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-35536 In Tornado before 6.5.5, cookie attribute injection could occur becaus ... | CVSS3: 7.2 | 0% Низкий | 4 месяца назад | |
GHSA-fqwm-6jpj-5wxc Tornado has cookie attribute injection via .RequestHandler.set_cookie | CVSS3: 7.2 | 0% Низкий | 4 месяца назад | |
RLSA-2026:19189 Moderate: python-tornado security update | 2 месяца назад | |||
RLSA-2026:19034 Moderate: python-tornado security update | 2 месяца назад | |||
RLSA-2026:13670 Moderate: python-tornado security update | 3 месяца назад | |||
RLSA-2026:13641 Moderate: python-tornado security update | 3 месяца назад | |||
ELSA-2026-19189 ELSA-2026-19189: python-tornado security update (MODERATE) | около 2 месяцев назад | |||
ELSA-2026-13670 ELSA-2026-13670: python-tornado security update (MODERATE) | 3 месяца назад | |||
ELSA-2026-13641 ELSA-2026-13641: python-tornado security update (MODERATE) | 3 месяца назад |
Уязвимостей на страницу