Cyber Resilience

CWE · MITRE source

CWE-1004Sensitive Cookie Without 'HttpOnly' Flag

Abstraction: Variant · CVEs in our corpus: 42

The product uses a cookie to store sensitive information, but the cookie is not marked with the HttpOnly flag.

Last updated: 20 August 2026 13:14 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: mostly · 2 mapping(s) from 1 framework(s): CSF 2.0 2 (mostly)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A02:2025 Security Misconfiguration.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.AT-02
  • PR.PS-06
  • SC-23 Session Authenticity
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2025-26844 7.39.80.00412025-05-08
CVE-2021-42115 6.48.10.01242021-11-30
CVE-2025-272236.27.50.02072025-10-27
CVE-2021-3706 6.17.50.01102021-09-15
CVE-2026-251366.08.10.00262026-02-25
CVE-2024-41685 5.97.50.00502024-07-26
CVE-2026-355755.98.00.00242026-04-07
CVE-2022-21939 5.77.50.00552023-02-09
CVE-2026-42239 5.78.10.00282026-05-07
CVE-2020-27658 5.57.10.01312020-10-29
CVE-2025-57424 5.57.30.00252025-09-29
CVE-2026-257335.57.30.00262026-02-25
CVE-2019-8283 5.36.50.01192019-06-07
CVE-2021-39210 5.36.50.01012021-09-15
CVE-2024-478335.06.50.00252024-10-09
CVE-2025-24318 5.06.80.00342025-02-28
CVE-2026-0696 5.06.50.00362026-01-16
CVE-2026-57948 5.06.80.00132026-06-29
CVE-2022-25172 4.86.10.01022022-05-12
CVE-2025-47289 4.86.30.00222025-06-02
CVE-2026-257344.76.10.00292026-02-25
CVE-2026-257354.76.10.00292026-02-25
CVE-2026-257364.76.10.00292026-02-25
CVE-2020-6267 4.55.40.00782020-07-14
CVE-2022-4630 4.55.30.00632022-12-21