# CVE-2026-25479

## Summary

- **CVE ID:** CVE-2026-25479
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
- **CWE:** CWE-185
- **Published:** Feb 9, 2026
- **Last Modified:** Mar 12, 2026

## Description

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows regex metacharacters to retain special meaning (e.g., . matches any character). This enables a bypass where an attacker supplies a host that matches the regex but is not the intended literal hostname. This vulnerability is fixed in 2.20.0.

## Affected Products

- litestar-org — litestar (< 2.20.0)

## References

- [CNA](https://github.com/litestar-org/litestar/security/advisories/GHSA-93ph-p7v4-hwh4)
- [CNA](https://github.com/litestar-org/litestar/commit/06b36f481d1bfea6f19995cfb4f203aba45c4ace)
- [CNA](https://docs.litestar.dev/2/release-notes/changelog.html#2.20.0)
- [CNA](https://github.com/litestar-org/litestar/releases/tag/v2.20.0)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.33%
- **EPSS Percentile:** 25.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._