Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4197-1 | python-flask-cors security update |
EUVD |
EUVD-2025-6979 | Flask-CORS vulnerable to Improper Handling of Case Sensitivity |
Github GHSA |
GHSA-43qf-4rqw-9q2g | Flask-CORS vulnerable to Improper Handling of Case Sensitivity |
Ubuntu USN |
USN-7612-1 | Flask-CORS vulnerabilities |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 01 Aug 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flask-cors Project
Flask-cors Project flask-cors |
|
| CPEs | cpe:2.3:a:flask-cors_project:flask-cors:4.0.1:*:*:*:*:*:*:* | |
| Vendors & Products |
Flask-cors Project
Flask-cors Project flask-cors |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching treats them as case-insensitive. This misconfiguration can lead to significant security vulnerabilities, allowing unauthorized origins to access paths meant to be restricted, resulting in data exposure and potential data leaks. | |
| Title | Case-Insensitive Path Matching in corydolphin/flask-cors | |
| Weaknesses | CWE-178 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-11-03T19:34:42.290Z
Reserved: 2024-07-17T21:09:41.423Z
Link: CVE-2024-6866
Updated: 2025-03-20T17:47:45.479Z
Status : Modified
Published: 2025-03-20T10:15:34.620
Modified: 2025-11-03T20:17:04.130
Link: CVE-2024-6866
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:44:40Z
Debian DLA
EUVD
Github GHSA
Ubuntu USN