
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25479 is a host allowlist validation bypass vulnerability in the Litestar Python web framework, specifically in its AllowedHostsMiddleware component. The flaw allows unauthenticated remote attackers to bypass the configured host allowlist by supplying crafted Host headers that match unescaped regex metacharacters. It affects Litestar version 2.19.0 and was disclosed on February 8, 2026, with a patch released the same day in version 2.20.0. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is classified as CWE-185 (Incorrect Regular Expression): in litestar/middleware/allowed_hosts.py, configured host allowlist entries are compiled directly into regex patterns without escaping regex metacharacters such as . (dot), which in regex matches any character rather than a literal period (GitHub Advisory). For example, an allowlist entry of example.com generates the regex example.com, which matches not only example.com but also strings like exampleXcom. An attacker exploits this by sending an HTTP request with a crafted Host header (e.g., exampleXcom) that satisfies the flawed regex but is not the intended literal hostname. No authentication, privileges, or user interaction are required — only network access to the target application (Litestar Security Advisory). A public proof-of-concept demonstrating the bypass is included in the advisory (GitHub Advisory).
Successful exploitation defeats the AllowedHosts security control, which is a primary mitigation layer against Host header attacks. Depending on application behavior, this bypass can enable cache poisoning, manipulation of absolute URL construction, and password reset link poisoning — all of which can lead to partial confidentiality and integrity compromise (GitHub Advisory). Availability is not directly impacted, but the downstream consequences vary significantly based on how the application uses the Host header in its logic.
A public proof-of-concept is included in the official security advisory, demonstrating the bypass with a simple Python HTTP client sending a crafted Host header (Litestar Security Advisory). The vulnerability requires no authentication, no privileges, and no user interaction, making it trivially exploitable over the network. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.019% (0.000290), indicating a low current probability of active exploitation (GitHub Advisory). The vulnerability is not listed in the CISA KEV catalog.
AllowedHostsConfig to restrict accepted Host headers (e.g., configured with allowed_hosts=["example.com"]).example.com is allowed, send Host: exampleXcom (where X replaces the . that the regex treats as a wildcard).Host header:GET / HTTP/1.1
Host: exampleXcomHost headers that do not exactly match configured allowed hostnames but contain characters substituting for . (e.g., exampleXcom instead of example.com); unexpected Host header values in access logs that are accepted with HTTP 200 responses.Host headers that do not match the literal configured allowlist entries; absence of expected HTTP 400 rejections for non-allowlisted hosts.Upgrade Litestar to version 2.20.0 or later, which fixes the issue by applying re.escape() to all host allowlist entries before compiling them into regex patterns (Litestar Release v2.20.0, Patch Commit). No configuration-based workaround is available for the vulnerable version; upgrading is the only reliable remediation. Applications that do not use AllowedHostsConfig are not affected by this vulnerability.
The vulnerability was reported by researcher Sirdorblu and published by Litestar maintainer provinzkraut on February 8, 2026 (Litestar Security Advisory). No significant broader media coverage or notable community commentary beyond the official advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."