Cyber Resilience

CWE · MITRE source

CWE-1275Sensitive Cookie with Improper SameSite Attribute

Abstraction: Variant · CVEs in our corpus: 26

The SameSite attribute for sensitive cookies is not set, or an insecure value is used.

The SameSite attribute controls how cookies are sent for cross-domain requests. This attribute may have three values: 'Lax', 'Strict', or 'None'. If the 'None' value is used, a website may create a cross-domain POST HTTP request to another website, and the browser automatically adds cookies to this request. This may lead to Cross-Site-Request-Forgery (CSRF) attacks if there are no additional protections in place (such as Anti-CSRF tokens).

Last updated: 21 August 2026 14:15 UTC

Cumulative inbound coverage

How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.

Collective: partial · 1 mapping(s) from 1 framework(s): CAPEC 1 (partial)

See the full cumulative-coverage rollup →

OWASP Top 10 for Web (2025)

This weakness contributes to A01:2025 Broken Access Control.

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-01
  • PR.PS-06
  • SC-23 Session Authenticity
  • CM-6 Configuration Settings
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V3.3.2

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2024-6611 7.49.80.00662024-07-09
CVE-2023-53957 7.49.80.00582025-12-19
CVE-2026-8409 6.38.80.00142026-05-21
CVE-2026-8410 6.38.80.00142026-05-21
CVE-2026-8411 6.38.80.00132026-05-21
CVE-2026-8412 6.38.80.00132026-05-21
CVE-2026-8413 6.38.80.00132026-05-21
CVE-2026-8414 6.38.80.00132026-05-21
CVE-2026-8415 6.38.80.00132026-05-21
CVE-2026-8416 6.38.80.00132026-05-21
CVE-2026-8427 6.38.80.00132026-05-21
CVE-2026-8432 6.38.80.00132026-05-21
CVE-2026-8433 6.38.80.00132026-05-21
CVE-2026-8434 6.38.80.00132026-05-21
CVE-2025-24897 5.68.20.00132025-02-11
CVE-2026-738475.06.80.00172026-08-14
CVE-2026-1697 4.96.50.00122026-02-26
CVE-2026-8435 4.86.50.00112026-05-21
CVE-2022-38386 4.75.90.00462024-05-01
CVE-2024-42212 4.35.40.00242025-05-05
CVE-2024-30155 4.25.50.00212025-03-26
CVE-2025-24387 3.74.80.00152025-03-10
CVE-2025-52628 3.74.60.00192026-02-03
CVE-2025-361343.23.70.00302025-11-25
CVE-2026-55688 3.24.00.00222026-07-01