CVE-2026-25479 | litestar-org litestar up to 2.19.x litestar.middleware.allowed_hosts incorrect regex (GHSA-93ph-p7v4-hwh4)
A vulnerability classified as critical has been found in litestar-org litestar up to 2.19.x. This vulnerability affects the function litestar.middleware.allowed_hosts. The manipulation leads to incorrect regular expression.
This vulnerability is traded as CVE-2026-25479. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.