CVE-2017-11173 — Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com doma — CVE Database · The Intelligence Room