CVE-2026-91991
6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Summary
Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| tornadoweb | tornado | 6.5.5 < 6.5.8 | affected |
| tornadoweb | tornado | 6.5.8 | unaffected |
Weaknesses
- CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
References
- https://github.com/tornadoweb/tornado/security/advisories/GHSA-wwv5-g3v4-889x
- https://www.vulncheck.com/advisories/tornado-before-6.5.8-cookie-attribute-injection-via-capitalized-kwargs
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.