CVE-2024-6839

MEDIUM

flask-cors < 6.0.0 - Improper CORS Policy Enforcement via Regex Pattern Priority Mismatch

Title source: llm
STIX 2.1

Description

corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. This mismatch in regex pattern priority allows unauthorized cross-origin access to sensitive data or functionality, potentially exposing confidential information and increasing the risk of unauthorized actions by malicious actors.

Scores

CVSS v3 5.3
EPSS 0.0058
EPSS Percentile 69.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-41
Status published
Products (2)
flask-cors_project/flask-cors 4.0.1
pypi/flask-cors 0 - 6.0.0PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026