# CVE-2026-91991

## Summary

- **CVE ID:** CVE-2026-91991
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N)
- **CWE:** CWE-113
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.

## Affected Products

- tornadoweb — tornado (6.5.5)
- tornadoweb — tornado (6.5.8)

## References

- [CNA](https://github.com/tornadoweb/tornado/security/advisories/GHSA-wwv5-g3v4-889x)
- [CNA](https://www.vulncheck.com/advisories/tornado-before-6.5.8-cookie-attribute-injection-via-capitalized-kwargs)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.22%
- **EPSS Percentile:** 12.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._