
CVE-2026-25479 Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into rege… https://www.cve.org/CVERecord?id=CVE-2026-25479
Post summary
The post discloses CVE‑2026‑25479 affecting Litestar’s allowed_hosts middleware before version 2.20.0, where allowlist entries are improperly compiled into regex, but it does not provide any PoC, exploit, patch, or evidence of active exploitation.


