Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-48817Medium· 5.3Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
CVE-2026-48818High· 7.5Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
CVE-2026-54282Low· 3.7Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVE-2026-48710Medium· 6.5CISA KEVPoCStarlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…
CVE-2025-62727High· 7.5PoCStarlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
CVE-2025-54121Medium· 5.3Starlette has possible denial-of-service vector when parsing large files in multipart forms
CVE-2024-47874None· 0.0Starlette Denial of service (DoS) via multipart/form-data
CVE-2023-29159Low· 3.7Starlette has Path Traversal vulnerability in StaticFiles
CVE-2023-30798High· 7.5MultipartParser denial of service with too many fields or files
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.