Dev.to
7/3/2026

FIFA World Cup 2026 Stadium Security Scan
Short summary
A security audit of 16 FIFA World Cup 2026 stadium websites revealed universal gaps in Content-Security-Policy headers, inconsistent HSTS implementation, and one stadium with a completely unprotected session cookie. The findings highlight standard misconfigurations found on most websites: missing security headers, weak cookie protections, and absent DNSSEC. High-traffic sites don't necessarily mean well-configured security unless someone is actively monitoring.
- •All 16 stadium sites had weak/missing CSP headers; 9 had HSTS problems
- •One site exposed an unprotected session cookie with zero security flags (missing Secure, HttpOnly, SameSite)
- •Same standard misconfigurations found everywhere—not exotic issues
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



