Fix
CORP (Cross-Origin-Resource-Policy)
Allows a resource to declare whether it can be requested from other origins (helps COEP / prevents leaks).
InfoCategory: headers
Recommended fix (typical)
Use 'same-origin' or 'same-site' for sensitive resources. Use 'cross-origin' only when you intentionally allow broad reuse.
Example
Cross-Origin-Resource-Policy: same-site