Cookie Chaos: How to bypass __Host and __Secure cookie prefixes

2 todsacerdoti 1 9/3/2025, 3:13:35 PM portswigger.net ↗

Comments (1)

nomoreofthat · 1h ago
That’s clever! Disappointing response from Django if that means they’re not going to fix it… I could understand it being outside the scope of their official vulnerability classification/process/whatever, but it’s still a clear correctness bug.