Impact
This vulnerability arises from an incomplete fix in Tornado versions before 6.5.8, allowing attackers to craft capitalized or legacy keyword arguments to the set_cookie method. By inserting semicolon‑delimited data into parameters such as Domain, Path or SameSite, an attacker can inject arbitrary cookie attributes that bypass the library’s validation logic. The flaw is a form of HTTP response splitting (CWE‑113) and could result in weakened cookie security, potentially enabling session hijacking or cross‑site request forgery if the cookie attributes are manipulated to be less restrictive.
Affected Systems
All installations of the Tornado web framework released prior to version 6.5.8 are affected. The vulnerability applies to the Tornado product distributed by the tornadoweb organization, regardless of the deployment platform, and requires any user or application that merges set_cookie calls with capitalized keyword arguments to be examined.
Risk and Exploitability
The CVSS score of 6.3 categorizes this flaw as moderate severity. EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been documented. Based on the description, the attack vector is inferred to be remote: an attacker who can remotely invoke the set_cookie API – for example through a crafted HTTP request to a vulnerable application – can embed malicious data. The exploit does not require elevated privileges or pre-existing code injection; it relies solely on the user‑controllable arguments supplied to set_cookie.
OpenCVE Enrichment