In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
"https://github.com/pypa/advisory-database/blob/main/vulns/tornado/PYSEC-2026-2287.yaml"