MEDIUM6.5
PYSEC-2026-3539
sanic-cors contains an improper regular expression in the try_match() function
Details
sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match without end-anchoring. This allows an attacker to bypass CORS origin allowlists by registering a domain that begins with a trusted origin string, to gain unauthorized access to cross-origin requests for authenticated resources.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/sanic-cors
Introduced in:
0No fixed version published yet for sanic-cors (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-37737[ADVISORY]
- https://github.com/ashleysommer/sanic-cors[PACKAGE]
- https://github.com/ashleysommer/sanic-cors/blob/master/sanic_cors/core.py[WEB]
- https://github.com/npbhatter17/security-advisories/blob/main/CVE-2026-37737-sanic-cors-advisory.md[WEB]
- https://pypi.org/project/Sanic-Cors[WEB]
- https://pypi.org/project/sanic-cors[PACKAGE]
- https://github.com/advisories/GHSA-94jw-hqvj-vw74[ADVISORY]