CVE-2026-91991
Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
- EPSS probability
- 0.22%
- CWE
- CWE-113
- Published
- 2026-09-15
- Last modified
- 2026-09-15
Affected products
- tornadoweb tornado
- tornadoweb tornado
Weakness type
Related vulnerabilities
- CVE-2026-34520 — AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass
- CVE-2025-53007 — arduino-esp32 vulnerable to CRLF injection in WebServer.cpp
- CVE-2021-0268 — Junos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks.
- CVE-2024-52875 — An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE
- CVE-2025-61689 — HTTP.jl vulnerable to Header injection/Response splitting via header construction.
- CVE-2025-53094 — ESPAsyncWebServer Vulnerable to CRLF Injection in AsyncWebHeader.cpp
- CVE-2025-59151 — Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injection
- CVE-2026-67289 — FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection