CVE-2025-21269

CVSS v3 Score
4.3
Medium

Vulnerability Description

Windows HTML Platforms Security Feature Bypass Vulnerability

CVSS:4.3(Medium)

corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to...

CWE-412024
CVSS:4.3(Medium)

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

CWE-412025