PT-2026-92105 · Tornado · Tornado

·

CVE-2026-91991

·

Published

2026-09-01

·

Updated

2026-09-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tornado versions prior to 6.5.8
Description An incomplete fix for cookie attribute injection allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to the set cookie() function. The validation loop only rejects specific characters for lowercase keys such as name, domain, path, and samesite. However, the deprecated **kwargs path writes values directly into the Morsel without validation. Because Morsel. setitem is case-insensitive, using capitalized parameters like Domain, Path, or SameSite bypasses the validation loop, enabling the injection of semicolon-delimited data to modify cookie security attributes, such as forcing or dropping Secure, HttpOnly, or SameSite flags.
Recommendations Update Tornado to version 6.5.8 or later. As a temporary workaround, avoid using capitalized or legacy keyword arguments in the set cookie() function.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-OZ84157
CVE-2026-91991
GHSA-WWV5-G3V4-889X
OESA-2026-4034
OESA-2026-4035
OESA-2026-4036
OESA-2026-4037
SUSE-SU-2026:4403-1
SUSE-SU-2026:4404-1

Affected Products

Tornado