logo

HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)

ID: 081161af-db85-5224-9a3d-f2b2b2f51112

STIX ID: report--081161af-db85-5224-9a3d-f2b2b2f51112

Feed Name: SANS ISC Diary

Threat Score
25/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

...
...

Observed honeypot traffic included a non-standard X-Vercel-Set-Bypass-Cookie header (value 'samesite-none-secure') likely intended to set a bypass cookie on Vercel deployments to relax protections; the header differs from documented Vercel bypass options and may enable persistence of a protection bypass or exposure of secrets. The request was proxied and the author did not confirm active exploitation, noting only that the header's undocumented value is suspicious and merits further investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.