Tornado Improper Handling of Invalid Use of Special Elements Vulnerability - CVE-2026-35536
In Tornado before 6.5.5 cookie attribute injection could occur because the domain path and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.