Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows regex metacharacters to retain special meaning (e.g., . matches any character). This enables a bypass where an attacker supplies a host that matches the regex but is not the intended literal hostname. This vulnerability is fixed in 2.20.0.
Cite this page
CVE-2026-25479. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-25479
Use CWE-185, Litestar vendor hub and Litestar product page to widen CVE-2026-25479 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-52581, CVE-2026-25478 and CVE-2026-25480 for nearby disclosures in the same product family.