{"id":"CVE-2021-32677","aliases":["GHSA-8h2j-cgx8-6xv7","PYSEC-2021-100"],"title":"Cross-Site Request Forgery (CSRF) in FastAPI","summary":"Cross-Site Request Forgery (CSRF) in FastAPI","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","vendor":"fastapi","product":"fastapi","ecosystem":"pip","affected":["fastapi < 0.65.2"],"patched":["fastapi 0.65.2"],"published":"2021-06-10","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-8h2j-cgx8-6xv7","references":[{"url":"https://github.com/tiangolo/fastapi/security/advisories/GHSA-8h2j-cgx8-6xv7"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32677"},{"url":"https://github.com/tiangolo/fastapi/commit/fa7e3c996edf2d5482fff8f9d890ac2390dede4d"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/fastapi/PYSEC-2021-100.yaml"},{"url":"https://github.com/tiangolo/fastapi"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MATAWX25TYKNEKLDMKWNLYDB34UWTROA"}],"tags":["osv","pip"],"epss":0.00722,"epssPercentile":0.51937,"ingestedAt":"2026-07-08T18:25:47.497Z","slug":"CVE-2021-32677","body":"## Overview\n\n### Impact\n\nFastAPI versions lower than `0.65.2` that used cookies for authentication in path operations that received JSON payloads sent by browsers were vulnerable to a Cross-Site Request Forgery (CSRF) attack.\n\nIn versions lower than `0.65.2`, FastAPI would try to read the request payload as JSON even if the `content-type` header sent was not set to `application/json` or a compatible JSON media type (e.g. `application/geo+json`).\n\nSo, a request with a content type of `text/plain` containing JSON data would be accepted and the JSON data would be extracted.\n\nBut requests with content type `text/plain` are exempt from [CORS](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS) preflights, for being considered [Simple requests](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS#simple_requests). So, the browser would execute them right away including cookies, and the text content could be a JSON string that would be parsed and accepted by the FastAPI application.\n\n### Patches\n\nThis is fixed in FastAPI `0.65.2`.\n\nThe request data is now parsed as JSON only if the `content-type` header is `application/json` or another JSON compatible media type like `application/geo+json`.\n\n### Workarounds\n\nIt's best to upgrade to the latest FastAPI.\n\nBut still, it would be possible to add a middleware or a dependency that checks the `content-type` header and aborts the request if it is not `application/json` or another JSON compatible content type.\n\n### References\n\n* [CORS on Mozilla web docs](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS)\n* [This answer on StackExchange](https://security.stackexchange.com/questions/157528/ways-to-bypass-browsers-cors-policy/157531#157531)\n* [OWASP CSRF](https://owasp.org/www-community/attacks/csrf)\n* Fixed in PR [#2118](https://github.com/tiangolo/fastapi/pull/2118)\n\n### For more information\n\nIf you have any questions or comments, write to [security@tiangolo.com](mailto:security@tiangolo.com)\n\n## Affected packages\n\n- `fastapi < 0.65.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `fastapi 0.65.2`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}