> USN-8198-1: Tornado vulnerabilities
[DATE: 22/04/2026 17:52]
[LANGUAGE: EN]
It was discovered that Tornado incorrectly handled parsing of large
multipart request bodies. An attacker could possibly use this issue to
cause a denial of service. (CVE-2026-31958)
It was discovered that Tornado did not properly validate characters in
cookie values. An attacker could possibly use this issue to inject
arbitrary cookie attributes. (CVE-2026-35536)