All fixes

Fix a CORS subdomain wildcard match

cors-subdomain-bypass

A pattern matching any subdomain also matches one an attacker registers or takes over. List the exact origins you trust instead of a pattern.

Why this matters

Your site trusts subdomains that match a pattern. Exploitable only if an attacker compromises or registers a matching subdomain first.

Express

  1. 1 Do not use regex or substring matching for origin validation
  2. 2 Use exact string comparison against a Set
javascript
// BAD: origin.endsWith(".example.com")
// GOOD:
const ALLOWED = new Set([
  "https://app.example.com",
  "https://www.example.com",
]);
app.use(cors({
  origin: (origin, cb) => cb(null, ALLOWED.has(origin)),
}));

Does your app still have this?

Scan your domain