Cookie Bomb
A cookie bomb fills a user’s cookie jar with enough data that subsequent requests to a target origin carry an oversized Cookie header. If an intermediary or application rejects those requests, the affected user can be locked out of the site while other users remain unaffected. Broad cookie scope can extend the impact to related subdomains.[1][2]
HackerOne report 57356 provides a practical example of this user-specific denial of service.[1]
For broader background on cookie-based attacks and browser limits, see The Cookie Monster in Your Browsers.[2]