What’s the oauth_callback value you’re using when making your request to oauth/request_token? Does it have a fully-qualified protocol, domain name, path, etc?
I’m definitely thinking the jessionid has something to do with it here – I don’t think Twitter is setting that so much as it becoming some kind of artifact from a possibly misconstructed oauth_callback value.
Hope this helps.