The Wire · Showcase
CONSUL-K8S PATCHES TORNADO COOKIE INJECTION FLAW
By RepoJournal · Filed · About HashiCorp
Consul-K8s shipped an emergency security fix overnight for a cookie attribute injection vulnerability in Tornado that could expose your gateway API layer.
Consul-K8s upgraded Tornado from 6.3.2 to 6.5.5 to patch GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) [1], a CWE-159 improper input handling flaw that allows attackers to inject malicious cookie attributes. This affects the control-plane gateway API stack and hits your security boundary if you're running Consul service mesh on Kubernetes. The fix is already merged [2] — it's a straightforward dependency bump with no breaking changes. Meanwhile, three nightly snapshots dropped across the Nomad ecosystem [3][4][5], but these are development builds for testing only and not recommended for production. The real story is Consul-K8s: patch before your next gateway deployment.
Action items
- → Upgrade consul-k8s to the latest patch with Tornado 6.5.5 before next production deploy hashicorp/consul-k8s [immediate]
- → Monitor your gateway API logs for any cookie-related exploits in the past 24 hours hashicorp/consul-k8s [immediate]
- → Review Nomad nightly builds if you're testing experimental features — otherwise skip hashicorp/nomad-driver-podman [monitor]
References
- [1] security: upgrade tornado 6.3.2 -> 6.5.5 to fix GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) (#5297) hashicorp/consul-k8s
- [2] security: upgrade tornado 6.3.2 -> 6.5.5 to fix GHSA-fqwm-6jpj-5wxc (CVE-2026-35536) ↗ hashicorp/consul-k8s
- [3] nightly ↗ hashicorp/nomad-driver-podman
- [4] nightly ↗ hashicorp/nomad-autoscaler
- [5] nightly ↗ hashicorp/nomad-pack
FAQ
- What changed in HashiCorp on May 9, 2026?
- Consul-K8s shipped an emergency security fix overnight for a cookie attribute injection vulnerability in Tornado that could expose your gateway API layer.
- What should HashiCorp teams do about it?
- Upgrade consul-k8s to the latest patch with Tornado 6.5.5 before next production deploy • Monitor your gateway API logs for any cookie-related exploits in the past 24 hours • Review Nomad nightly builds if you're testing experimental features — otherwise skip
- Which HashiCorp repositories shipped on May 9, 2026?
- hashicorp/consul-k8s, hashicorp/nomad-driver-podman, hashicorp/nomad-autoscaler, hashicorp/nomad-pack