← volver
CVE-2026-25479

Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patterns

CVSS 6.5 MEDIUMEPSS 0.3%CWE-185
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows regex metacharacters to retain special meaning (e.g., . matches any character). This enables a bypass where an attacker supplies a host that matches the regex but is not the intended literal hostname. This vulnerability is fixed in 2.20.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Productos afectados
litestar-org · litestar

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →