CVE-2026-35536: Tornado has cookie attribute injection via .RequestHandler.set_cookie
(updated )
In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-35536 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →