PT-2026-92105 · Tornado · Tornado
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tornado versions prior to 6.5.8
Description
An incomplete fix for cookie attribute injection allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to the
set cookie() function. The validation loop only rejects specific characters for lowercase keys such as name, domain, path, and samesite. However, the deprecated **kwargs path writes values directly into the Morsel without validation. Because Morsel. setitem is case-insensitive, using capitalized parameters like Domain, Path, or SameSite bypasses the validation loop, enabling the injection of semicolon-delimited data to modify cookie security attributes, such as forcing or dropping Secure, HttpOnly, or SameSite flags.Recommendations
Update Tornado to version 6.5.8 or later.
As a temporary workaround, avoid using capitalized or legacy keyword arguments in the
set cookie() function.Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tornado