In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-tornado | May 6, 2026 | May 5, 2026 |
| Amazon Linux Ami 2 | — | Upgrade python3-tornado-docUpgrade python-tornado-debuginfoUpgrade python3-tornado-debuginfoUpgrade python-tornado-docUpgrade python-tornadoUpgrade python3-tornado | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade python-tornado-debugsourceUpgrade python-tornado-docUpgrade python3.13-tornado-debuginfoUpgrade python3.13-tornado-debugsourceUpgrade python3.13-tornado-docUpgrade python3.13-tornadoUpgrade python3-tornadoUpgrade python3-tornado-debuginfo | May 4, 2026 | Apr 3, 2026 |
| Debian | — | Upgrade python-tornado | Apr 6, 2026 | Apr 6, 2026 |
| Oracle_linux | — | Upgrade python3-tornado | May 6, 2026 | Apr 3, 2026 |
| Redhat_linux | — | Upgrade python-tornadoUpgrade python3-tornado-debuginfoUpgrade python-tornado-debugsourceUpgrade python-tornado-debuginfoUpgrade python3-tornadoUpgrade python-tornado-doc | May 7, 2026 | Apr 3, 2026 |
| Rocky_linux | — | Upgrade python3-tornadoUpgrade python3-tornado-debuginfoUpgrade python-tornado-debugsource | May 11, 2026 | May 6, 2026 |
| Ubuntu | — | Upgrade python3-tornado (Ubuntu Pro)Upgrade python-tornado (Ubuntu Pro)Upgrade python3-tornado | Apr 23, 2026 | Apr 3, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Apr 3, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub