Cross-Origin Resource Sharing (CORS)
A browser mechanism that lets a server declare, through HTTP headers, which other origins may read its responses, relaxing the same-origin policy in a controlled way for legitimate cross-site requests.
By default, the browser's same-origin policy prevents scripts loaded from one origin, defined by scheme, host and port, from reading responses from another. CORS allows exceptions: the server returns headers such as Access-Control-Allow-Origin and Access-Control-Allow-Credentials to indicate which origins may read a response and whether cookies may be included. For requests that are not simple, such as those with custom headers or methods like PUT and DELETE, the browser first sends an OPTIONS preflight request to check permission.
CORS is essential for single-page applications, APIs consumed by front ends on different domains and third-party integrations. It is enforced by browsers, which means it controls what web pages can read rather than who can call an API; non-browser clients such as scripts and servers ignore it entirely.
Misconfiguration is common and can expose sensitive data, for example reflecting any Origin header back with credentials allowed, trusting the null origin, or using loose pattern matching that accepts attacker-controlled domains. Policies should use an explicit allow-list of trusted origins, never combine a wildcard with credentials, which browsers reject in any case, and never be treated as an authentication or authorisation control. The OWASP Top 10 2021 lists CORS misconfiguration among broken access control weaknesses.
Key points
- Relaxes the browser's same-origin policy for approved origins.
- Preflight OPTIONS requests check permission for non-simple requests.
- Enforced only by browsers; it is not an API access control.
- Reflecting arbitrary origins with credentials allowed is a serious misconfiguration.
Where AiVibe comes in
AiVedha.ai's automated website security audit covers CORS among more than 170 checks, with severity ratings and remediation steps in its report.