Wildcard Origin with Credentials
Express.js applications configure CORS with Access-Control-Allow-Origin: * while also setting Access-Control-Allow-Credentials: true. This combination is both invalid (browsers reject it) and insecure, indicating an attempt to allow authenticated cross-origin requests from any domain.