Cookies leaked to the wrong host: a URL parsing differential in tough-cookie A URL parsing differential in tough-cookie, a widely used Node.js cookie library, can leak cookies to the wrong host, according to a report from hackzero.ai. The vulnerability arises from inconsistent parsing of URLs with special characters, potentially allowing an attacker to receive cookies intended for a different domain. The issue affects applications using tough-cookie versions prior to the fix. Article URL: https://hackzero.ai/learn/tough-cookie-cookie-leak Comments URL: https://news.ycombinator.com/item?id=49178070 Points: 1 Comments: 0