Apache Helix REST CORS Vulnerability in Versions Through 2.0.0 Allows Unrestricted Cross-Origin Requests

Vulnerability

A Cross-Origin Resource Sharing (CORS) vulnerability has been identified in the Apache Helix REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in all platforms through version 2.0.0. This vulnerability allows remote attackers, controlling a web page visited by an authorized user, to read responses from and send cross-origin requests to administrative REST endpoints. The issue arises because the CORS filter indiscriminately allows requests from any origin, permits credentials, and reflects arbitrary method and header values in preflight responses.

Impact

Exploitation of this vulnerability could lead to unauthorized access to administrative REST endpoints, allowing attackers to read responses or issue requests that could affect the application's state or data.

Remediation

Users are advised to upgrade to Apache Helix version 2.0.1, which addresses this CORS vulnerability.

Added: Jul 9, 2026, 8:26 AM
Updated: Jul 9, 2026, 8:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.5
exploitability
4.2
remediation
7.7
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.