<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:11:31 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:13641 — Moderate: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:13641</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: python3-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado-python: Tornado: Denial of Service via large multipart bodies (CVE-2026-31958)
  * tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments (CVE-2026-35536)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: python3-tornado&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tornado-python: Tornado: Denial of Service via large multipart bodies (CVE-2026-31958)
  * tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments (CVE-2026-35536)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:13641</guid>
    </item>
    <item>
      <title>bdu:2026-07217</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-07217</link>
      <description>bdu:2026-07217</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-07217</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-35536</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-35536</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: py3-tornado, Alpaquita:stream: py3-tornado&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:25: py3-tornado, Alpaquita:stream: py3-tornado&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-35536</guid>
    </item>
    <item>
      <title>BREW-jupyterlab-CVE-2026-35536 — Tornado has incomplete validation of cookie attributes</title>
      <link>https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-35536</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;Values passed to the `domain`, `path`, and `samesite` arguments of `RequestHandler.set_cookie` were not completely validated in versions of Tornado prior to 6.5.5. In particular, semicolons would be allowed, which could be used to inject attacker-controlled values for other cookie attributes.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: jupyterlab&lt;/p&gt;
&lt;p&gt;Values passed to the `domain`, `path`, and `samesite` arguments of `RequestHandler.set_cookie` were not completely validated in versions of Tornado prior to 6.5.5. In particular, semicolons would be allowed, which could be used to inject attacker-controlled values for other cookie attributes.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-jupyterlab-cve-2026-35536</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0901 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</link>
      <description>certfr-2026-avi-0901</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0901</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AZ09261 — Security fixes for CVE-2023-46136, CVE-2024-12797, CVE-2024-34069, CVE-2024-49766, CVE-2024-49767, CVE-2025-62727, CVE-…</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: airflow-3&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the airflow-3 package. These issues are resolved in later releases. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-az09261</guid>
    </item>
    <item>
      <title>EUVD-2026-280118</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280118</link>
      <description>EUVD-2026-280118</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280118</guid>
    </item>
    <item>
      <title>fkie_cve-2026-35536</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-35536</link>
      <description>&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-35536</guid>
    </item>
    <item>
      <title>GHSA-fqwm-6jpj-5wxc — Tornado has cookie attribute injection via .RequestHandler.set_cookie</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fqwm-6jpj-5wxc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to `.RequestHandler.set_cookie` were not checked for crafted characters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to `.RequestHandler.set_cookie` were not checked for crafted characters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fqwm-6jpj-5wxc</guid>
    </item>
    <item>
      <title>OESA-2026-1903 — python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1903</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-tornado, openEuler:20.03-LTS-SP4: python-tornado, openEuler:22.03-LTS-SP4: python-tornado, openEuler:24.03-LTS: python-tornado, openEuler:24.03-LTS-SP1: python-tornado, openEuler:24.03-LTS-SP2: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is an open source version of the scalable, non-blocking web server and tools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom &amp;amp;quot;reason&amp;amp;quot; phrases (the &amp;amp;quot;Not Found&amp;amp;quot; in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.(CVE-2025-67724)&lt;/p&gt;
&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.(CVE-2026-35536)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-tornado, openEuler:20.03-LTS-SP4: python-tornado, openEuler:22.03-LTS-SP4: python-tornado, openEuler:24.03-LTS: python-tornado, openEuler:24.03-LTS-SP1: python-tornado, openEuler:24.03-LTS-SP2: python-tornado&lt;/p&gt;
&lt;p&gt;Tornado is an open source version of the scalable, non-blocking web server and tools.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header injection) or in HTML in the default error page (where it could be used for XSS) and can be exploited by passing untrusted or malicious data into the reason argument. Used by both RequestHandler.set_status and tornado.web.HTTPError, the argument is designed to allow applications to pass custom &amp;amp;quot;reason&amp;amp;quot; phrases (the &amp;amp;quot;Not Found&amp;amp;quot; in HTTP/1.1 404 Not Found) to the HTTP status line (mainly for non-standard status codes). This issue is fixed in version 6.5.3.(CVE-2025-67724)&lt;/p&gt;
&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.(CVE-2026-35536)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1903</guid>
    </item>
    <item>
      <title>PYSEC-2026-2287</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2287</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: tornado&lt;/p&gt;
&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2287</guid>
    </item>
    <item>
      <title>RHSA-2026:13641 — Red Hat Security Advisory: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:13641</link>
      <description>&lt;p&gt;tornado-python: Tornado: Denial of Service via large multipart bodies tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tornado-python: Tornado: Denial of Service via large multipart bodies tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:13641</guid>
    </item>
    <item>
      <title>RHSA-2026:20572 — Red Hat Security Advisory: python-tornado security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:20572</link>
      <description>&lt;p&gt;tornado-python: Tornado: Denial of Service via large multipart bodies tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tornado-python: Tornado: Denial of Service via large multipart bodies tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:20572</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-35536</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35536</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:25.10: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: python-tornado, Ubuntu:Pro:18.04:LTS: python-tornado, Ubuntu:Pro:22.04:LTS: python-tornado, Ubuntu:24.04:LTS: python-tornado, Ubuntu:25.10: python-tornado, Ubuntu:26.04:LTS: python-tornado&lt;/p&gt;
&lt;p&gt;In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-35536</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2933 — Splunk SOAR: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2933</guid>
    </item>
  </channel>
</rss>
