Critical Vulnerabilities in Tornado Affect Ubuntu 26.04 LTS

Critical Vulnerabilities in Tornado Affect Ubuntu 26.04 LTS

First seen 29 Apr 2026, 02:58 UTC UbuntuLinuxsecurity 94% similarity 70.5

Article Content

Browse articles
ThreatCluster

Two significant vulnerabilities have been identified in Tornado, a web server framework used in Ubuntu 26.04 LTS. CVE-2026-31958, published on 2026-03-11, allows attackers to exploit improper handling of large multipart request bodies, potentially leading to denial of service. Another vulnerability, CVE-2026-35536, published on 2026-04-03, involves inadequate validation of cookie values, enabling attackers to inject arbitrary cookie attributes. Both vulnerabilities were addressed in the recent update USN-8198-2. Users of Ubuntu 26.04 LTS are advised to update their systems to mitigate these risks. The vulnerabilities could impact a wide range of applications relying on Tornado. The updates are crucial for maintaining system integrity and security. Ubuntu Pro offers ten-year security coverage for affected packages.

Key Points: • Two critical vulnerabilities in Tornado affect Ubuntu 26.04 LTS. • CVE-2026-31958 can lead to denial of service attacks. • CVE-2026-35536 allows for arbitrary cookie attribute injection.

ThreatCluster AI

Timeline

2026-03-11
CVE-2026-31958 published
2026-04-03
CVE-2026-35536 published
2026-04-28
USN-8198-2 update released for Ubuntu 26.04 LTS

Community

Browse all →

Tracked Entities in This Story