<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T20:34:01.788967+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:13641</id>
    <title>ALSA-2026:13641 — Moderate: python-tornado security update</title>
    <updated>2026-10-02T20:34:02.126507+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: python3-tornado</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* tornado-python: Tornado: Denial of Service via large multipart bodies (CVE-2026-31958)
  * tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments (CVE-2026-35536)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:13641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07217</id>
    <title>bdu:2026-07217</title>
    <updated>2026-10-02T20:34:02.126621+00:00</updated>
    <content>bdu:2026-07217</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07217"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-35536</id>
    <title>BELL-CVE-2026-35536</title>
    <updated>2026-10-02T20:34:02.126640+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: py3-tornado, Alpaquita:stream: py3-tornado</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-35536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-35536</id>
    <title>BREW-jupyterlab-CVE-2026-35536 — Tornado has incomplete validation of cookie attributes</title>
    <updated>2026-10-02T20:34:02.126662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: jupyterlab</p>
<p>Values passed to the `domain`, `path`, and `samesite` arguments of `RequestHandler.set_cookie` were not completely validated in versions of Tornado prior to 6.5.5. In particular, semicolons would be allowed, which could be used to inject attacker-controlled values for other cookie attributes.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-35536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</id>
    <title>certfr-2026-avi-0901 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T20:34:02.126685+00:00</updated>
    <content>certfr-2026-avi-0901</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</id>
    <title>Withdrawn: CLEANSTART-2026-AZ09261 — Security fixes for CVE-2023-46136, CVE-2024-12797, CVE-2024-34069, CVE-2024-49766, CVE-2024-49767, CVE-2025-62727, CVE-…</title>
    <updated>2026-10-02T20:34:02.126702+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-280118</id>
    <title>EUVD-2026-280118</title>
    <updated>2026-10-02T20:34:02.126729+00:00</updated>
    <content>EUVD-2026-280118</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-280118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35536</id>
    <title>fkie_cve-2026-35536</title>
    <updated>2026-10-02T20:34:02.126742+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-35536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fqwm-6jpj-5wxc</id>
    <title>GHSA-fqwm-6jpj-5wxc — Tornado has cookie attribute injection via .RequestHandler.set_cookie</title>
    <updated>2026-10-02T20:34:02.126763+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to `.RequestHandler.set_cookie` were not checked for crafted characters.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fqwm-6jpj-5wxc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1903</id>
    <title>OESA-2026-1903 — python-tornado security update</title>
    <updated>2026-10-02T20:34:02.126783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: python-tornado, openEuler:20.03-LTS-SP4: python-tornado, openEuler:22.03-LTS-SP4: python-tornado, openEuler:24.03-LTS: python-tornado, openEuler:24.03-LTS-SP1: python-tornado, openEuler:24.03-LTS-SP2: python-tornado</p>
<p>Tornado is an open source version of the scalable, non-blocking web server and tools.

Security Fix(es):</p>
<p>Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom &amp;quot;reason&amp;quot; phrases (the &amp;quot;Not Found&amp;quot; in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.(CVE-2025-67724)</p>
<p>In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.(CVE-2026-35536)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1903"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2287</id>
    <title>PYSEC-2026-2287</title>
    <updated>2026-10-02T20:34:02.126821+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: tornado</p>
<p>In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:13641</id>
    <title>RHSA-2026:13641 — Red Hat Security Advisory: python-tornado security update</title>
    <updated>2026-10-02T20:34:02.126841+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tornado-python: Tornado: Denial of Service via large multipart bodies tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:13641"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:20572</id>
    <title>RHSA-2026:20572 — Red Hat Security Advisory: python-tornado security update</title>
    <updated>2026-10-02T20:34:02.126861+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tornado-python: Tornado: Denial of Service via large multipart bodies tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:20572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35536</id>
    <title>UBUNTU-CVE-2026-35536</title>
    <updated>2026-10-02T20:34:02.126879+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:25.10: python-tornado, Ubuntu:26.04:LTS: python-tornado</p>
<p>In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35536"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</id>
    <title>WID-SEC-W-2026-2933 — Splunk SOAR: Mehrere Schwachstellen</title>
    <updated>2026-10-02T20:34:02.126906+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933"/>
  </entry>
</feed>
