CVE-2026-25478: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25478 is a CORS origin allowlist bypass vulnerability in the Litestar Python web framework caused by unescaped regex metacharacters in allowed origins. Discovered and disclosed on February 8, 2026, it affects Litestar versions up to and including 2.19.0, with version 2.20.0 containing the fix. The vulnerability carries a CVSS v3.1 base score of 7.4 (High) per the GitHub Security Advisory, or 6.5 (Medium) per Feedly's estimate (GitHub Advisory, Litestar Advisory).

Technical details

The root cause (CWE-942: Permissive Cross-domain Policy with Untrusted Domains) lies in CORSConfig.allowed_origins_regex, which compiles the configured origin allowlist into a Python regex without first escaping regex metacharacters. Because the dot (.) in a domain like https://good.example is treated as a wildcard regex character rather than a literal period, an attacker-controlled origin such as https://goodXexample satisfies the fullmatch() check and receives an Access-Control-Allow-Origin response header. The fix (commit eb87703) applies re.escape() to each allowed origin before regex compilation, while preserving intentional wildcard (*) behavior via a UUID placeholder substitution (GitHub Advisory, Fix Commit).

Impact

Successful exploitation allows an attacker-controlled website to read cross-origin responses from a victim's authenticated Litestar application session in their browser. The confidentiality impact is high — sensitive data returned by authenticated endpoints (e.g., user profile data, tokens, API responses) can be exfiltrated without the victim's knowledge. Integrity and availability are not affected; the scope is changed (browser security boundary crossed), but lateral movement within server infrastructure is not directly enabled (Litestar Advisory).

Exploitability

A proof-of-concept is publicly available in the GitHub Security Advisory, demonstrating the bypass with a minimal server and client script. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.031% (6th percentile), indicating low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Identify a target application: Locate a Litestar-based web application (version ≤ 2.19.0) that uses CORSConfig with a specific allow_origins list and has allow_credentials=True enabled.
  2. Analyze the allowed origins: Determine the configured allowed origins (e.g., https://good.example) — this may be inferred from CORS response headers on legitimate cross-origin requests.
  3. Craft a bypass origin: Register or control a domain that matches the unescaped regex pattern. For example, if https://good.example is allowed, the origin https://goodXexample (replacing . with any character) will bypass the regex check.
  4. Host a malicious page: Create an attacker-controlled webpage at the bypass origin that uses JavaScript's fetch() or XMLHttpRequest with credentials: 'include' to send cross-origin requests to the target application's authenticated endpoints.
  5. Lure the victim: Use phishing or social engineering to direct an authenticated user to the malicious page.
  6. Exfiltrate data: The browser sends the request with the victim's session cookies; the server responds with Access-Control-Allow-Origin: https://goodXexample and Access-Control-Allow-Credentials: true, allowing the malicious page's JavaScript to read and exfiltrate the response body (GitHub Advisory, Litestar Advisory).

Indicators of compromise

  • Network: HTTP requests to authenticated API endpoints with an Origin header that does not exactly match any configured allowed origin but contains characters substituting for . (e.g., https://goodXexample when https://good.example is allowed); presence of Access-Control-Allow-Origin response headers reflecting unexpected origin values.
  • Logs: Web server/application access logs showing cross-origin requests from unfamiliar or suspicious origin domains that nonetheless receive a permissive Access-Control-Allow-Origin header; repeated cross-origin requests to sensitive endpoints from the same IP with varying origin headers.
  • Browser/Client: Victim browser network traffic showing fetch or XHR requests to the application with credentials: include originating from an unexpected third-party domain.

Mitigation and workarounds

Upgrade Litestar to version 2.20.0 or later, which applies re.escape() to all configured allowed origins before regex compilation, eliminating the metacharacter bypass (Fix Commit, v2.20.0 Release). As a temporary workaround prior to upgrading, avoid using allow_credentials=True in CORSConfig unless strictly necessary, and consider using the allow_origin_regex parameter with a manually crafted, properly escaped regex instead of the allow_origins list. Additionally, audit all endpoints that return sensitive data when credentials are enabled and consider adding server-side authorization checks independent of CORS headers (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher "Sirdorblu" and published by Litestar maintainer provinzkraut on February 8, 2026. No significant broader media coverage or notable public researcher commentary beyond the GitHub advisory has been identified at this time (Litestar Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management