Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes. | |
| Title | Tornado before 6.5.8 Cookie Attribute Injection via Capitalized kwargs | |
| First Time appeared |
Tornadoweb
Tornadoweb tornado |
|
| Weaknesses | CWE-113 | |
| CPEs | cpe:2.3:a:tornadoweb:tornado:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Tornadoweb
Tornadoweb tornado |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:18:32.408Z
Reserved: 2026-09-15T11:11:13.311Z
Link: CVE-2026-91991
No data.
Status : Received
Published: 2026-09-15T16:17:58.293
Modified: 2026-09-15T16:17:58.293
Link: CVE-2026-91991
No data.
OpenCVE Enrichment
No data.
-
CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')