CVE-2024-6866 Information
Mar 21, 2025
cve
Description
corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the try_match function which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive but the regex matching treats them as case-insensitive. This misconfiguration can lead to significant security vulnerabilities allowing unauthorized origins to access paths meant to be restricted resulting in data exposure and potential data leaks.
Reference
https://huntr.com/bounties/808c11af-faee-43a8-824b-b5ab4f62b9e6
Share on: