CVE-2026-25479Disclosure(litestar / litestar)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows regex metacharacters to retain special meaning (e.g., . matches any character). This enables a bypass where an attacker supplies a host that matches the regex but is not the intended literal hostname. This vulnerability is fixed in 2.20.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-185

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litestar

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
litestar

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-09: 3Technical Details · 2026-02-09: 302-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25479 Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into rege… https://www.cve.org/CVERecord?id=CVE-2026-25479

    Post summary

    The post discloses CVE‑2026‑25479 affecting Litestar’s allowed_hosts middleware before version 2.20.0, where allowlist entries are improperly compiled into regex, but it does not provide any PoC, exploit, patch, or evidence of active exploitation.

    00010140
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25479 Host Validation Bypass Vulnerability in Litestar ASGI Framework Before 2.20.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25479

    Post summary

    The text announces a host‑validation bypass vulnerability (CVE‑2026‑25479) affecting Litestar ASGI Framework versions before 2.20.0, but provides no PoC, exploit details, patch, or evidence of active exploitation.

    0000076
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25479: The Dot That Killed the Host: Litestar AllowedHosts Bypass A classic regular expression logic flaw in Litestar's AllowedHostsMiddleware allows attackers to bypass host header validation. By failing to escape the dot character in config... https://cvereports.com/reports/CVE-2026-25479

    Post summary

    The report discloses a regex logic flaw in Litestar's AllowedHostsMiddleware enabling host header bypass, but lacks details on PoC, exploitation, patches, or mitigation.

    0000021
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitestarlitestar---

Explore more