cd /news/ai-safety/cookies-leaked-to-the-wrong-host-a-u… · home topics ai-safety article
[ARTICLE · art-87056] src=hackzero.ai ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Cookies leaked to the wrong host: a URL parsing differential in tough-cookie

A URL parsing differential in tough-cookie, a widely used Node.js cookie library, can leak cookies to the wrong host, according to a report from hackzero.ai. The vulnerability arises from inconsistent parsing of URLs with special characters, potentially allowing an attacker to receive cookies intended for a different domain. The issue affects applications using tough-cookie versions prior to the fix.

read1 min views1 publishedAug 5, 2026

Article URL:

https://hackzero.ai/learn/tough-cookie-cookie-leak Comments URL: https://news.ycombinator.com/item?id=49178070

Points: 1

── more in #ai-safety 4 stories · sorted by recency
── more on @tough-cookie 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/cookies-leaked-to-th…] indexed:0 read:1min 2026-08-05 ·