Skip to content

Cross-Origin Resource Sharing (CORS) misconfigurations: wildcard origins, null origin bypasses, and credential exposure

Understand CORS security risks: why 'Access-Control-Allow-Origin: *' is misunderstood, how dynamic origin reflection leads to full account takeover, and how to safely configure CORS.

By BugSnaps Security Research · · 7 min read

Cross-Origin Resource Sharing (CORS) is a browser mechanism that relaxes the Same-Origin Policy (SOP) to allow web applications running at one origin to make authenticated requests to an API at a different origin. Misconfiguring CORS headers is one of the quickest ways to expose authenticated user data to third-party attackers.

The deadly combination: reflected origin with credentials

The browser's Same-Origin Policy strictly prohibits setting `Access-Control-Allow-Origin: *` while simultaneously setting `Access-Control-Allow-Credentials: true`. To work around this restriction, developers frequently write dynamic reflection logic that blindly reads the incoming `Origin` header and echoes it back in the response.

  • Origin reflection: echoing any arbitrary `Origin: https://evil-attacker.com` alongside `Access-Control-Allow-Credentials: true`, enabling malicious sites to steal authenticated data via simple JavaScript `fetch()` calls.
  • Null origin trust: allowing `Origin: null`, which attackers can trigger using sandboxed iframes (`<iframe sandbox='allow-scripts'>`).
  • Weak regex parsing: matching `bugsnaps.in` using regexes like `/bugsnaps.in/` without anchoring, allowing origins like `https://bugsnaps.in.evil.com` or `https://notbugsnaps.in`.

Safe CORS architecture

Maintain a strict, hardcoded server-side allowlist of trusted origins. Validate incoming Origin headers against the exact array. If the origin is not explicitly in the allowlist, do not return CORS headers at all.

BugSnaps MyPentest automatically tests CORS endpoints with diverse origin probes, identifying insecure reflection, null origin trust, and credential exposure.

Run a real pentest on your app - free.

Sign in, prove you own the domain, and MyPentest maps and tests it. No credit card.