Fix a CORS subdomain wildcard match
cors-subdomain-bypass
A pattern matching any subdomain also matches one an attacker registers or takes over. List the exact origins you trust instead of a pattern.
Why this matters
Your site trusts subdomains that match a pattern. Exploitable only if an attacker compromises or registers a matching subdomain first.
Frameworks
Express
- 1 Do not use regex or substring matching for origin validation
- 2 Use exact string comparison against a Set
javascript
// BAD: origin.endsWith(".example.com")
// GOOD:
const ALLOWED = new Set([
"https://app.example.com",
"https://www.example.com",
]);
app.use(cors({
origin: (origin, cb) => cb(null, ALLOWED.has(origin)),
}));Does your app still have this?
Scan your domain