Improper Neutralization of Special Elements in Output Used by a Downstream Component in Tornado - CVE-2026-35536
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject attacker-controlled cookie attributes.
The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in RequestHandler.set_cookie when processing the domain, path, and samesite arguments. A remote attacker can supply input containing semicolons to inject attacker-controlled cookie attributes.
User interaction is required for exploitation.
Affected software
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
openEuler
Anolis OS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python-tornado (Ubuntu package)
python-tornado (Red Hat package)
python3-tornado
python3-tornado-doc
python-tornado-debuginfo
python-tornado-help
python-tornado-debugsource
python-tornado
How to mitigate CVE-2026-35536
python-tornado (Ubuntu package) - addressed in versions 4.2.1-1ubuntu3.1+esm3, 4.5.3-1ubuntu0.2+esm3, 6.0.3+really5.1.1-3ubuntu0.1~esm5, 6.1.0-3ubuntu0.1~esm5, 6.4.0-1ubuntu0.5, 6.4.2-3ubuntu0.3, 6.5.4-0.1ubuntu0.1
python-tornado (Red Hat package) - addressed in versions 4.2.1-5.el7_9.3, 6.4.2-1.el9_4.2, 6.4.2-1.el10_0.2, 6.5.5-1.el9_7.1, 6.5.5-1.el10_1.1
python3-tornado - update to 6.5.2-3
python3-tornado-doc - update to 6.5.2-3
python-tornado-debuginfo - update to 6.5-4
python3-tornado - update to 6.5-4
python-tornado-help - update to 6.5-4
python-tornado-debugsource - update to 6.5-4
python-tornado - update to 6.5-4
python-tornado - addressed in versions 6.5.7-1.fc43, 6.5.7-1.fc44, 6.5.7-1.fc45
External References
Related Security Bulletins
- Multiple vulnerabilities in Tornado
- openEuler update for python-tornado
- Anolis OS update for python-tornado
- Ubuntu update for python-tornado
- Ubuntu update for python-tornado
- Red Hat Enterprise Linux 10 update for python-tornado
- Red Hat Enterprise Linux 9 update for python-tornado
- Red Hat Enterprise Linux 10 update for python-tornado
- Red Hat Enterprise Linux 9 update for python-tornado
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for python-tornado
- Fedora 45 update for python-tornado
- Fedora 43 update for python-tornado
- Fedora 44 update for python-tornado