CVE-2026-33533: Http Server Cors Wildcard

A wildcard `*` is hardcoded as the value for the `Access-Control-Allow-Origin` header in `send_header`. This permissive CORS policy allows any origin to read the response. If the HTTP server exposes sensitive data or APIs, this can result in cross-origin data exfiltration via simple requests or preflight bypasses. Configure allowed origins explicitly instead

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-33533-http-server-cors-wildcard --engine opengrep

Description

A wildcard `*` is hardcoded as the value for the `Access-Control-Allow-Origin` header in `send_header`. This permissive CORS policy allows any origin to read the response. If the HTTP server exposes sensitive data or APIs, this can result in cross-origin data exfiltration via simple requests or preflight bypasses. Configure allowed origins explicitly instead