Pattern
Mis-scoped Cookie Attributes
cookie-scope-samesite-httponly-mismatch
Cross-subdomain and cross-site cookies fail to attach or be readable because the cookie domain, SameSite, and HttpOnly semantics don’t match the client’s redirect/request flow, breaking authentication and token handling.