{"slug": "cookies-leaked-to-the-wrong-host-a-url-parsing-differential-in-tough-cookie", "title": "Cookies leaked to the wrong host: a URL parsing differential in tough-cookie", "summary": "A URL parsing differential in tough-cookie, a widely used Node.js cookie library, can leak cookies to the wrong host, according to a report from hackzero.ai. The vulnerability arises from inconsistent parsing of URLs with special characters, potentially allowing an attacker to receive cookies intended for a different domain. The issue affects applications using tough-cookie versions prior to the fix.", "body_md": "Article URL: \nhttps://hackzero.ai/learn/tough-cookie-cookie-leak\n\nComments URL: \nhttps://news.ycombinator.com/item?id=49178070\n\nPoints: 1\n\n# Comments: 0", "url": "https://wpnews.pro/news/cookies-leaked-to-the-wrong-host-a-url-parsing-differential-in-tough-cookie", "canonical_source": "https://hackzero.ai/learn/tough-cookie-cookie-leak", "published_at": "2026-08-05 02:58:59+00:00", "updated_at": "2026-08-05 03:22:14.023234+00:00", "lang": "en", "topics": ["ai-safety"], "entities": ["tough-cookie", "hackzero.ai"], "alternates": {"html": "https://wpnews.pro/news/cookies-leaked-to-the-wrong-host-a-url-parsing-differential-in-tough-cookie", "markdown": "https://wpnews.pro/news/cookies-leaked-to-the-wrong-host-a-url-parsing-differential-in-tough-cookie.md", "text": "https://wpnews.pro/news/cookies-leaked-to-the-wrong-host-a-url-parsing-differential-in-tough-cookie.txt", "jsonld": "https://wpnews.pro/news/cookies-leaked-to-the-wrong-host-a-url-parsing-differential-in-tough-cookie.jsonld"}}