MALFORMED

Test IDCOOK-MALFORMED
CategoryCookies
ScoredNo
RFC LevelN/A
Expected2xx or 400

What it sends

Completely malformed cookie value (===;;;) — tests parser crash resilience.

GET /echo HTTP/1.1\r\n
Host: localhost:8080\r\n
Cookie: ===;;;\r\n
\r\n

Why it matters

Garbage cookie values with no valid key=value structure can crash naive parsers that split on = without bounds checking.

Verdicts

  • Pass — 2xx or 400
  • Fail — 500 (crash)

Sources