Back to Guides
Guide5 October 2026

What does CORS stand for and why should developers care?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. What does CORS stand for?
  2. Why does CORS matter for web security?
  3. How does the browser enforce CORS?
  4. Which HTTP headers control CORS?
  5. When is a preflight request sent?
  6. Common CORS misconfigurations to avoid
  7. How to fix a CORS error in development
  8. Example: Configuring CORS in Express (Node.js)
  9. Example: Configuring CORS in Nginx
  10. When should you disable CORS?
  11. Summary

Key takeaways

What does CORS stand for?

CORS stands for Cross - Origin Resource Sharing. It is a browser - enforced policy that defines how a web page can request resources from a domain other than the one that served the page.

Why does CORS matter for web security?

CORS matters because it mitigates the risk of cross - origin attacks such as CSRF and data leakage. Without CORS, a malicious site could freely read responses from another site the user is logged into, exposing sensitive data.

How does the browser enforce CORS?

When a script makes a cross - origin request, the browser adds an Origin header. The target server must respond with an Access-Control-Allow-Origin header that matches the request's origin (or a wildcard *). If the header is missing or mismatched, the browser blocks the response and logs a CORS error in the console.

Which HTTP headers control CORS?

HeaderPurpose
Access-Control-Allow-OriginSpecifies which origins may access the resource.
Access-Control-Allow-MethodsLists HTTP methods (GET, POST, etc.) allowed for cross - origin requests.
Access-Control-Allow-HeadersIndicates which custom request headers are permitted.
Access-Control-Allow-CredentialsAllows cookies and HTTP authentication to be sent with the request when set to true.
Access-Control-Max-AgeCaches the preflight response for a given number of seconds.

When is a preflight request sent?

A preflight OPTIONS request is sent when the actual request uses a method other than GET, HEAD, or POST, or when it includes custom headers. The server must respond with the appropriate Access-Control-Allow-* headers; otherwise the browser aborts the request.

Common CORS misconfigurations to avoid

How to fix a CORS error in development

  1. Identify the request URL and the origin shown in the browser console.
  2. Update the server configuration to include that origin in Access-Control-Allow-Origin.
  3. If credentials are needed, set Access-Control-Allow-Credentials:true and ensure the origin is not *.
  4. Restart the server and retest the request.

Example: Configuring CORS in Express (Node.js)

const express = require('express');
const cors = require('cors');
const app = express();

// Allow only https://example.com to access the API
app.use(cors({
 origin: 'https://example.com',
 methods: ['GET','POST','PUT','DELETE'],
 credentials: true
}));

app.get('/data', (req, res) => {
 res.json({msg: 'CORS configured correctly'});
});

app.listen(3000);

Example: Configuring CORS in Nginx

location /api/ {
 if ($http_origin ~* "^https?://(www\.)?example\.com$") {
 add_header 'Access-Control-Allow-Origin' "$http_origin" always;
 add_header 'Access-Control-Allow-Methods' 'GET, POST, OPTIONS' always;
 add_header 'Access-Control-Allow-Headers' 'Authorization, Content-Type' always;
 add_header 'Access-Control-Allow-Credentials' 'true' always;
 }
 if ($request_method = OPTIONS) {
 add_header 'Access-Control-Max-Age' 1728000;
 add_header 'Content-Type' 'text/plain charset=UTF-8';
 add_header 'Content-Length' 0;
 return 204;
 }
}

When should you disable CORS?

Disabling CORS (by not sending any Access-Control-* headers) is appropriate for resources that are only intended to be accessed from the same origin, such as internal admin pages. Public APIs that need to be consumed by third - party sites should always send explicit CORS headers.

Summary

CORS (Cross - Origin Resource Sharing) is a critical browser security mechanism that governs how resources are shared across origins. Understanding the required headers, handling preflight requests, and avoiding common misconfigurations helps developers prevent CORS errors and protect users from cross - origin attacks.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary