CVE-2026-37737

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match without end-anchoring. This allows an attacker to bypass CORS origin allowlists by registering a domain that begins with a trusted origin string, to gain unauthorized access to cross-origin requests for authenticated resources.

Published 2026-06-05. Last modified 2026-06-17.