fastapi-guard is vulnerable to Security pipeline bypass via CORS preflight short-circuit
50
Medium Risk
Affected versions of this package are vulnerable to a security-check bypass on CORS preflight requests. Because the library's security middleware runs after the CORS layer, browser preflight requests skip IP banning, rate limiting, and suspicious-pattern detection, letting attackers probe the allowed origins and methods without triggering the protections.
You are affected if you are using a version that falls within the vulnerable range.
fastapi-guard is vulnerable to Security pipeline bypass via CORS preflight short-circuit in versions 5.0.0 - 5.2.0.
Upgrade the fastapi-guard library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant