security
Apr 28, 2026
By Teun
Ubuntu 26.04 gets Tornado security fixes for two flaws
Ubuntu has released USN-8198-2 to fix two vulnerabilities in Tornado for Ubuntu 26.04 LTS. The issues could allow a denial of service through large multipart request bodies or let an attacker inject arbitrary cookie attributes.
Ubuntu has released USN-8198-2 to address two security issues in Tornado, the Python web server and web toolkit. The update applies to Ubuntu 26.04 LTS and brings the package to python3-tornado 6.5.4-0.1ubuntu0.1.
According to the advisory, the fix corresponds to issues first covered in USN-8198-1 and now extended to the Ubuntu 26.04 LTS release. Ubuntu said a standard system update will install the necessary changes.
⚡ New to this?
This is a security update for Tornado, a Python web framework used to build servers and web apps. One bug could let an attacker overload a service until it stops responding, and the other could change how cookies are handled, which can affect login sessions and other web behavior.
A CVE is a tracked security flaw, and a denial of service means a system becomes unavailable instead of being stolen or taken over. If you run software that depends on Tornado, these fixes matter because they reduce the chance of downtime or unexpected session-related behavior.
🦞 OpenClaw angle
If you run self-hosted Python services on Ubuntu 26.04 LTS, update the base system and rebuild any containers that pin python3-tornado so the fixed package is included. For agent workflows that accept uploads or structured web input, add request-size limits and rate limits so a large multipart body cannot tie up the service.
Also review any code that sets cookies through Tornado. Make sure your automation does not trust user-controlled cookie fields and that session cookies are validated server-side, not just by browser behavior.
The first issue involved Tornado incorrectly handling the parsing of large multipart request bodies. Multipart request bodies are commonly used when a web app accepts file uploads or form data split into parts. In this case, an attacker could potentially trigger a denial of service, which means making a service stop responding or become unavailable.
The flaw is tracked as CVE-2026-31958. Ubuntu said the bug was discovered in Tornado’s request parsing code, and the security impact was limited to denial of service rather than direct code execution.
The second issue affected how Tornado validated characters in cookie values. Cookies are small pieces of data a browser stores and sends back to a website, often used for sessions or preferences. According to the advisory, poor validation could let an attacker inject arbitrary cookie attributes.
That issue is tracked as CVE-2026-35536. Injecting cookie attributes can alter how a browser or application treats a cookie, which can affect application behavior and security controls.
Ubuntu’s notice says the problem can be corrected by updating the system packages to the fixed version. For Ubuntu 26.04 LTS, that means installing python3-tornado 6.5.4-0.1ubuntu0.1.
The advisory also points users to Ubuntu Pro, which the company says provides ten years of security coverage for more than 25,000 packages in the Main and Universe repositories, free for up to five machines.