Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35536

25
FAUCET Score

CVE-2026-35536 identifies a cookie attribute injection vulnerability in Tornado versions prior to 6.5.5, stemming from insufficient validation of crafted characters in cookie domain, path, and samesite arguments. This high-severity flaw (CVSS 7.2) has a low attack complexity and can be exploited over the network, potentially leading to low impact on confidentiality and integrity. Currently, there is no indication of active exploitation, no public exploit code available, and minimal community discussion regarding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.5.5CPE matchmatch criteria
cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*
>= 0, < 6.5.5CPE match
cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 6th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

pippatch availablevia ghsa
Product: tornadoFixed in: 6.5.5
ubuntupatch availablevia ubuntu_usn
Product: python-tornado (resolute)Fixed in: 6.5.4-0.1ubuntu0.1
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (2)

ubuntuUSN-8198-2

Tornado vulnerabilities

Apr 28, 2026
pipGHSA-fqwm-6jpj-5wxchigh

Tornado has cookie attribute injection via .RequestHandler.set_cookie

Apr 3, 2026

References

github.com / tornadoweb/tornado/releases/tag/v6.5.5
Product
github.com / tornadoweb/tornado/security/advisories/GHSA-78cv-mqj4-43f7
Vendor Advisory