Skip to content

cookie-secure and cookie-httponly are raising false positives #194

Description

@Corb3nik

The following Set-Cookie header is raising findings for the cookie-secure and cookie-httponly checks, when both flags are there.

Set-Cookie: SNID=[redacted]_[redacted]-V5Aj-EDUJxQXg; expires=Tue, 07-Apr-2026 21:03:10 GMT; path=/verify; domain=.google.com; Secure; HttpOnly; SameSite=lax

Metadata

Metadata

Assignees

No one assigned

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions