RepoJournal
HashiCorp

@hashicorp

Terraform, Vault, Consul — infra-as-code for ops teams

Pick a date

The Wire · Showcase

CONSUL-K8S PATCHES TORNADO COOKIE INJECTION FLAW

By RepoJournal · Filed · About HashiCorp

Consul-K8s shipped an emergency security fix overnight for a cookie attribute injection vulnerability in Tornado that could expose your gateway API layer.

Consul-K8s upgraded Tornado from 6.3.2 to 6.5.5 to patch GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) [1], a CWE-159 improper input handling flaw that allows attackers to inject malicious cookie attributes. This affects the control-plane gateway API stack and hits your security boundary if you're running Consul service mesh on Kubernetes. The fix is already merged [2] — it's a straightforward dependency bump with no breaking changes. Meanwhile, three nightly snapshots dropped across the Nomad ecosystem [3][4][5], but these are development builds for testing only and not recommended for production. The real story is Consul-K8s: patch before your next gateway deployment.

Action items

References

  1. [1] security: upgrade tornado 6.3.2 -> 6.5.5 to fix GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) (#5297) hashicorp/consul-k8s
  2. [2] security: upgrade tornado 6.3.2 -> 6.5.5 to fix GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) ↗ hashicorp/consul-k8s
  3. [3] nightly ↗ hashicorp/nomad-driver-podman
  4. [4] nightly ↗ hashicorp/nomad-autoscaler
  5. [5] nightly ↗ hashicorp/nomad-pack

FAQ

What changed in HashiCorp on May 9, 2026?
Consul-K8s shipped an emergency security fix overnight for a cookie attribute injection vulnerability in Tornado that could expose your gateway API layer.
What should HashiCorp teams do about it?
Upgrade consul-k8s to the latest patch with Tornado 6.5.5 before next production deploy • Monitor your gateway API logs for any cookie-related exploits in the past 24 hours • Review Nomad nightly builds if you're testing experimental features — otherwise skip
Which HashiCorp repositories shipped on May 9, 2026?
hashicorp/consul-k8s, hashicorp/nomad-driver-podman, hashicorp/nomad-autoscaler, hashicorp/nomad-pack

Related across the cluster

For your repos

The showcase is a teaser.
Your wire is the product.

Same engine. Different stack. Below: what changes when the wire is yours.

Showcase wire

  • 14 famous open source orgs
  • One wire per day
  • Public, generic
  • Read on the web, when you remember

Your wire

  • Up to 1,500 of your repos - orgs, deps, vendors
  • Morning and evening briefs
  • Action items routed to your team
  • Slack delivery, email, breaking-news CVE alerts

Want a hands-on demo first? Ask a current user for an invite link.