cors-reflected-creds

CORS reflects arbitrary origin with credentials

CWE-942 — MITRE entryA05:2021 — Security MisconfigurationOWASP ASVS V14.5.3CVSS v3.1v 2026-04-18

Authoritative references

Sekrd runs this check automatically on every scan that covers web application surface. Findings link back to this page so reviewers can validate the rule against the cited standards.

Disagree with how this rule fires on your site? Open a dispute from the finding card in your scan report — we review every ticket.