Skip to content
Vulnerability field guide

CORS Misconfiguration

An overly permissive CORS policy lets a malicious site read responses meant only for the victim. Here is how reflecting the Origin header goes wrong, and how a strict allowlist fixes it.

1 article 3 min total Overview to advanced techniques