Sensitive Cookie Without 'HttpOnly' Flag in kasuganosoras/pigeon


Reported on

Oct 24th 2021


One or more cookies don't have the HttpOnly flag set. When a cookie is set with the HttpOnly flag, it instructs the browser that the cookie can only be accessed by the server and not by client-side scripts. This is an important security protection for session cookies.


If possible, you should set the HttpOnly flag for these cookies.

We have contacted a member of the kasuganosoras/pigeon team and are waiting to hear back a year ago
kasuganosoras validated this vulnerability a year ago
wtwver has been awarded the disclosure bounty
The fix bounty is now up for grabs
kasuganosoras confirmed that a fix has been merged on 9551f3 a year ago
The fix bounty has been dropped
to join this conversation