
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25478 is a CORS origin allowlist bypass vulnerability in the Litestar Python web framework caused by unescaped regex metacharacters in allowed origins. Discovered and disclosed on February 8, 2026, it affects Litestar versions up to and including 2.19.0, with version 2.20.0 containing the fix. The vulnerability carries a CVSS v3.1 base score of 7.4 (High) per the GitHub Security Advisory, or 6.5 (Medium) per Feedly's estimate (GitHub Advisory, Litestar Advisory).
The root cause (CWE-942: Permissive Cross-domain Policy with Untrusted Domains) lies in CORSConfig.allowed_origins_regex, which compiles the configured origin allowlist into a Python regex without first escaping regex metacharacters. Because the dot (.) in a domain like https://good.example is treated as a wildcard regex character rather than a literal period, an attacker-controlled origin such as https://goodXexample satisfies the fullmatch() check and receives an Access-Control-Allow-Origin response header. The fix (commit eb87703) applies re.escape() to each allowed origin before regex compilation, while preserving intentional wildcard (*) behavior via a UUID placeholder substitution (GitHub Advisory, Fix Commit).
Successful exploitation allows an attacker-controlled website to read cross-origin responses from a victim's authenticated Litestar application session in their browser. The confidentiality impact is high — sensitive data returned by authenticated endpoints (e.g., user profile data, tokens, API responses) can be exfiltrated without the victim's knowledge. Integrity and availability are not affected; the scope is changed (browser security boundary crossed), but lateral movement within server infrastructure is not directly enabled (Litestar Advisory).
A proof-of-concept is publicly available in the GitHub Security Advisory, demonstrating the bypass with a minimal server and client script. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.031% (6th percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).
CORSConfig with a specific allow_origins list and has allow_credentials=True enabled.https://good.example) — this may be inferred from CORS response headers on legitimate cross-origin requests.https://good.example is allowed, the origin https://goodXexample (replacing . with any character) will bypass the regex check.fetch() or XMLHttpRequest with credentials: 'include' to send cross-origin requests to the target application's authenticated endpoints.Access-Control-Allow-Origin: https://goodXexample and Access-Control-Allow-Credentials: true, allowing the malicious page's JavaScript to read and exfiltrate the response body (GitHub Advisory, Litestar Advisory).Origin header that does not exactly match any configured allowed origin but contains characters substituting for . (e.g., https://goodXexample when https://good.example is allowed); presence of Access-Control-Allow-Origin response headers reflecting unexpected origin values.Access-Control-Allow-Origin header; repeated cross-origin requests to sensitive endpoints from the same IP with varying origin headers.fetch or XHR requests to the application with credentials: include originating from an unexpected third-party domain.Upgrade Litestar to version 2.20.0 or later, which applies re.escape() to all configured allowed origins before regex compilation, eliminating the metacharacter bypass (Fix Commit, v2.20.0 Release). As a temporary workaround prior to upgrading, avoid using allow_credentials=True in CORSConfig unless strictly necessary, and consider using the allow_origin_regex parameter with a manually crafted, properly escaped regex instead of the allow_origins list. Additionally, audit all endpoints that return sensitive data when credentials are enabled and consider adding server-side authorization checks independent of CORS headers (GitHub Advisory).
The vulnerability was reported by researcher "Sirdorblu" and published by Litestar maintainer provinzkraut on February 8, 2026. No significant broader media coverage or notable public researcher commentary beyond the GitHub advisory has been identified at this time (Litestar Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."