All fixes

Stop trusting the null CORS origin

cors-null-origin

The null origin comes from sandboxed iframes and local files, so any page can claim it. Never put null in your Access-Control-Allow-Origin.

Why this matters

Your site allows data sharing with "null" origins, which can be faked using sandboxed iframes. Conditionally exploitable — requires crafting a specific attack page.

Nginx

  1. 1 Do not match 'null' in your origin map
nginx
map $http_origin $cors_origin {
    default "";
    # Remove this line:
    #   "null" "null";
    "https://app.example.com" $http_origin;
}

Does your app still have this?

Scan your domain