CORS Security Risk Assessment Form
Assess the CORS configuration of your application, identify cross-origin exposure, and record recommended remediation steps.
Application Context
Application or service name
*
Environment or deployment stage
*
Development
Staging
Production
Other
API or frontend URL or domain under review
*
Brief description of the application and required client origins
*
CORS Configuration Review
Access-Control-Allow-Origin
*
Restricted to approved origins
Wildcard (*)
Unknown
Credentials enabled
*
No
Yes
Unknown
Allowed methods limited to required methods
*
Yes
No
Unknown
Allowed headers restricted to necessary headers
*
Yes
No
Unknown
Exposed headers minimized
*
Yes
No
Unknown
Origin matching exactness
*
Exact match
Overly broad pattern
Unknown
Risk Rating and Findings
Overall CORS Risk Rating
*
Low Risk
1
2
3
4
5
6
7
8
9
Critical Risk
10
1 is Low Risk, 10 is Critical Risk
Highest-Risk Issue Observed
*
Evidence or Notes Supporting the Rating
Recommended Remediation Priority
*
Please Select
Low
Medium
High
Critical
Submit
Should be Empty: