CVE-2026-25479: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25479 is a host allowlist validation bypass vulnerability in the Litestar Python web framework, specifically in its AllowedHostsMiddleware component. The flaw allows unauthenticated remote attackers to bypass the configured host allowlist by supplying crafted Host headers that match unescaped regex metacharacters. It affects Litestar version 2.19.0 and was disclosed on February 8, 2026, with a patch released the same day in version 2.20.0. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-185 (Incorrect Regular Expression): in litestar/middleware/allowed_hosts.py, configured host allowlist entries are compiled directly into regex patterns without escaping regex metacharacters such as . (dot), which in regex matches any character rather than a literal period (GitHub Advisory). For example, an allowlist entry of example.com generates the regex example.com, which matches not only example.com but also strings like exampleXcom. An attacker exploits this by sending an HTTP request with a crafted Host header (e.g., exampleXcom) that satisfies the flawed regex but is not the intended literal hostname. No authentication, privileges, or user interaction are required — only network access to the target application (Litestar Security Advisory). A public proof-of-concept demonstrating the bypass is included in the advisory (GitHub Advisory).

Impact

Successful exploitation defeats the AllowedHosts security control, which is a primary mitigation layer against Host header attacks. Depending on application behavior, this bypass can enable cache poisoning, manipulation of absolute URL construction, and password reset link poisoning — all of which can lead to partial confidentiality and integrity compromise (GitHub Advisory). Availability is not directly impacted, but the downstream consequences vary significantly based on how the application uses the Host header in its logic.

Exploitability

A public proof-of-concept is included in the official security advisory, demonstrating the bypass with a simple Python HTTP client sending a crafted Host header (Litestar Security Advisory). The vulnerability requires no authentication, no privileges, and no user interaction, making it trivially exploitable over the network. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.019% (0.000290), indicating a low current probability of active exploitation (GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog.

Exploitation steps

  1. Identify target: Locate a web application built with Litestar version 2.19.0 that uses AllowedHostsConfig to restrict accepted Host headers (e.g., configured with allowed_hosts=["example.com"]).
  2. Analyze the allowlist: Determine the configured allowed hostnames (e.g., via error responses, documentation, or reconnaissance).
  3. Craft a bypass Host header: Construct a hostname that matches the unescaped regex but is not the literal allowed host — for example, if example.com is allowed, send Host: exampleXcom (where X replaces the . that the regex treats as a wildcard).
  4. Send the crafted request: Issue an HTTP GET or POST request to the target application with the crafted Host header:
    GET / HTTP/1.1
    Host: exampleXcom
  5. Achieve bypass: The server accepts the request (HTTP 200) instead of rejecting it (HTTP 400), bypassing the host allowlist control and enabling further Host header attacks such as cache poisoning or password reset link injection (GitHub Advisory, Litestar Security Advisory).

Indicators of compromise

  • Network: HTTP requests to the application with Host headers that do not exactly match configured allowed hostnames but contain characters substituting for . (e.g., exampleXcom instead of example.com); unexpected Host header values in access logs that are accepted with HTTP 200 responses.
  • Logs: Application access logs showing HTTP 200 responses for requests with Host headers that do not match the literal configured allowlist entries; absence of expected HTTP 400 rejections for non-allowlisted hosts.
  • Application Behavior: Cache entries or generated URLs containing unexpected or attacker-controlled hostnames; password reset emails with links pointing to unrecognized domains (GitHub Advisory).

Mitigation and workarounds

Upgrade Litestar to version 2.20.0 or later, which fixes the issue by applying re.escape() to all host allowlist entries before compiling them into regex patterns (Litestar Release v2.20.0, Patch Commit). No configuration-based workaround is available for the vulnerable version; upgrading is the only reliable remediation. Applications that do not use AllowedHostsConfig are not affected by this vulnerability.

Community reactions

The vulnerability was reported by researcher Sirdorblu and published by Litestar maintainer provinzkraut on February 8, 2026 (Litestar Security Advisory). No significant broader media coverage or notable community commentary beyond the official advisory has been identified.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management