Improper Neutralization of Special Elements in Output Used by a Downstream Component in Tornado - CVE-2026-35536

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Tornado - CVE-2026-35536

Published: April 27, 2026


Vulnerability identifier: #VU128148
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35536
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to inject attacker-controlled cookie attributes.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in RequestHandler.set_cookie when processing the domain, path, and samesite arguments. A remote attacker can supply input containing semicolons to inject attacker-controlled cookie attributes.

User interaction is required for exploitation.


Affected software

Tornado
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
openEuler
Anolis OS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python-tornado (Ubuntu package)
python-tornado (Red Hat package)
python3-tornado
python3-tornado-doc
python-tornado-debuginfo
python-tornado-help
python-tornado-debugsource
python-tornado

How to mitigate CVE-2026-35536

Install security update from vendor's website.

Tornado - update to 6.5.5
python-tornado (Ubuntu package) - addressed in versions 4.2.1-1ubuntu3.1+esm3, 4.5.3-1ubuntu0.2+esm3, 6.0.3+really5.1.1-3ubuntu0.1~esm5, 6.1.0-3ubuntu0.1~esm5, 6.4.0-1ubuntu0.5, 6.4.2-3ubuntu0.3, 6.5.4-0.1ubuntu0.1
python-tornado (Red Hat package) - addressed in versions 4.2.1-5.el7_9.3, 6.4.2-1.el9_4.2, 6.4.2-1.el10_0.2, 6.5.5-1.el9_7.1, 6.5.5-1.el10_1.1
python3-tornado - update to 6.5.2-3
python3-tornado-doc - update to 6.5.2-3
python-tornado-debuginfo - update to 6.5-4
python3-tornado - update to 6.5-4
python-tornado-help - update to 6.5-4
python-tornado-debugsource - update to 6.5-4
python-tornado - update to 6.5-4
python-tornado - addressed in versions 6.5.7-1.fc43, 6.5.7-1.fc44, 6.5.7-1.fc45

External References

Related Security Bulletins