Description
Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.
Published: 2026-09-15
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cookie Attribute Injection enabling modification of cookie security attributes such as Domain, Path or SameSite, which can compromise cookie confidentiality or integrity
Action: Patch
AI Analysis

Impact

This vulnerability arises from an incomplete fix in Tornado versions before 6.5.8, allowing attackers to craft capitalized or legacy keyword arguments to the set_cookie method. By inserting semicolon‑delimited data into parameters such as Domain, Path or SameSite, an attacker can inject arbitrary cookie attributes that bypass the library’s validation logic. The flaw is a form of HTTP response splitting (CWE‑113) and could result in weakened cookie security, potentially enabling session hijacking or cross‑site request forgery if the cookie attributes are manipulated to be less restrictive.

Affected Systems

All installations of the Tornado web framework released prior to version 6.5.8 are affected. The vulnerability applies to the Tornado product distributed by the tornadoweb organization, regardless of the deployment platform, and requires any user or application that merges set_cookie calls with capitalized keyword arguments to be examined.

Risk and Exploitability

The CVSS score of 6.3 categorizes this flaw as moderate severity. EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been documented. Based on the description, the attack vector is inferred to be remote: an attacker who can remotely invoke the set_cookie API – for example through a crafted HTTP request to a vulnerable application – can embed malicious data. The exploit does not require elevated privileges or pre-existing code injection; it relies solely on the user‑controllable arguments supplied to set_cookie.

Generated by OpenCVE AI on September 20, 2026 at 16:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Tornado to version 6.5.8 or later, which contains the full fix for the cookie attribute injection flaw
  • Ensure that all calls to set_cookie use only lower‑case keyword arguments and validate any user‑supplied data before including it in the cookie attributes
  • Audit custom middleware or frameworks that wrap Tornado’s set_cookie to confirm they do not expose capitalized keyword arguments to untrusted sources

Generated by OpenCVE AI on September 20, 2026 at 16:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-915
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.
Title Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs
First Time appeared Tornadoweb
Tornadoweb tornado
Weaknesses CWE-113
CPEs cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
Vendors & Products Tornadoweb
Tornadoweb tornado
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Tornadoweb Tornado
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T19:14:16.700Z

Reserved: 2026-09-15T11:11:13.311Z

Link: CVE-2026-91991

cve-icon Vulnrichment

Updated: 2026-09-21T19:13:51.244Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:58.293

Modified: 2026-09-21T20:17:39.740

Link: CVE-2026-91991

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:32Z

Links: CVE-2026-91991 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:15:18Z

Weaknesses
  • CWE-113

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

  • CWE-915

    Improperly Controlled Modification of Dynamically-Determined Object Attributes