Cookie Chaos: How to bypass __Host and __Secure cookie prefixes
2 todsacerdoti 1 9/3/2025, 3:13:35 PM portswigger.net ↗
Comments (1)
nomoreofthat · 1h ago
That’s clever! Disappointing response from Django if that means they’re not going to fix it… I could understand it being outside the scope of their official vulnerability classification/process/whatever, but it’s still a clear correctness bug.