THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-wwv5-g3v4-889x (low) — Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

[GHSA] GHSA-wwv5-g3v4-889x (low) — Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

highgithub_advisoriesPublished 2026-09-01

GHSA-wwv5-g3v4-889x Severity: low CVE: None

Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwargs` path in `set_cookie`

## Summary The CVE-2026-35536 fix added a validation loop that rejects `[\x00-\x20\x3b\x7f]`, but only for the hardcoded **lowercase** keys `name`/`domain`/`path`/`samesite`. The still-live deprecated `**kwarg

Indicators of compromise

Original source: https://github.com/advisories/GHSA-wwv5-g3v4-889x