CVE-2026-25478 | litestar-org litestar up to 2.19.x fullmatch cross-domain policy (GHSA-2p2x-hpg8-cqp2)
A vulnerability marked as problematic has been reported in litestar-org litestar up to 2.19.x. Affected by this issue is the function fullmatch. Performing a manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is reported as CVE-2026-25478. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.