<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T21:37:23.354066+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-jupyterlab-ghsa-wwv5-g3v4-889x</id>
    <title>BREW-jupyterlab-GHSA-wwv5-g3v4-889x — Tornado: Incomplete fix for CVE-2026-35536: cookie attribute injection re-opened via the legacy case-insensitive `**kwa…</title>
    <updated>2026-10-04T21:37:23.613234+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: jupyterlab</p>
<p>## Summary
The CVE-2026-35536 fix added a validation loop that rejects `[\x00-\x20\x3b\x7f]`, but only for the
hardcoded **lowercase** keys `name`/`domain`/`path`/`samesite`. The still-live deprecated `**kwargs` path
writes attacker-supplied attribute values straight into the `Morsel` with no validation, and because
`Morsel.__setitem__` is case-insensitive, a capitalized kwarg (`Domain=`, `Path=`, `SameSite=`, `Max-Age=`)
routes to the same reserved attribute while bypassing the loop — re-opening `;`-delimited attribute injection.</p>
<p>```python
self.set_cookie("sid", "abc", Domain="evil.com; Secure; SameSite=None")
#  -&gt; Set-Cookie: sid=abc; Domain=evil.com; Secure; SameSite=None; Path=/
# Sanity (the canonical lowercase named arg IS blocked):
self.set_cookie("sid", "abc", domain="evil.com; Secure")   # -&gt; http.cookies.CookieError
```</p>
<p>The patch's regression test (`SetCookieForbiddenCharHandler`) only exercises the four named params, never the
`**kwargs` path, so the gap is not regression-covered.</p>
<p>## Affected code
- `tornado/web.py` → `RequestHandler.set_cookie`: the validation loop covers only the lowercase named args;
  the trailing `if kwargs:` loop does `morsel[k] = v` with no character validation.</p>
<p>## Steps to reproduce
`GET /upper` (uses `Domain=` kwarg) emits `Set-Cookie: c_upper=v; Domain=evil.com; Secure; SameSite=None; Path=/`; `GET /lower` (uses lowercase
`domain=`) returns a `CookieError`.</p>
<p>## Impact
Injection of independent cookie attributes (force/drop `Secure`/`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-jupyterlab-ghsa-wwv5-g3v4-889x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-oz84157</id>
    <title>CLEANSTART-2026-OZ84157 — Tornado before 6</title>
    <updated>2026-10-04T21:37:23.613370+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: airflow-3</p>
<p>CVE-2026-91991 affects multiple packages. Tornado before 6. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-oz84157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-373180</id>
    <title>EUVD-2026-373180</title>
    <updated>2026-10-04T21:37:23.613407+00:00</updated>
    <content>EUVD-2026-373180</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-373180"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-91991</id>
    <title>fkie_cve-2026-91991</title>
    <updated>2026-10-04T21:37:23.613428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-91991"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jj9x-pjq2-f55m</id>
    <title>GHSA-jj9x-pjq2-f55m</title>
    <updated>2026-10-04T21:37:23.613467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jj9x-pjq2-f55m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-4034</id>
    <title>OESA-2026-4034 — python-tornado security update</title>
    <updated>2026-10-04T21:37:23.613495+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP1: python-tornado</p>
<p>Tornado is a Python web framework and asynchronous networking library, originally developed at FriendFeed. By using non-blocking network I/O, Tornado can scale to tens of thousands of open connections, making it ideal for long polling, WebSockets, and other applications that require a long-lived connection to each user.

Security Fix(es):</p>
<p>Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.(CVE-2023-54397)</p>
<p>Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.(CVE-2024-14029)</p>
<p>Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP requests.(CVE-2024-58384)</p>
<p>Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validatin…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-4034"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-91991</id>
    <title>UBUNTU-CVE-2026-91991</title>
    <updated>2026-10-04T21:37:23.613575+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:20.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:26.04:LTS: python-tornado</p>
<p>Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters like Domain, Path, or SameSite to bypass validation and modify cookie security attributes.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-91991"/>
  </entry>
</feed>
