{"id":"CVE-2025-54121","aliases":["GHSA-2c2j-9gv5-cj73","PYSEC-2026-1941"],"title":"Starlette has possible denial-of-service vector when parsing large files in multipart forms","summary":"Starlette has possible denial-of-service vector when parsing large files in multipart forms","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","vendor":"starlette","product":"starlette","ecosystem":"pip","affected":["starlette < 0.47.2"],"patched":["starlette 0.47.2"],"published":"2025-07-21","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:25.704876348Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-2c2j-9gv5-cj73","references":[{"url":"https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54121"},{"url":"https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1"},{"url":"https://github.com/encode/starlette"},{"url":"https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14"},{"url":"https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403"}],"tags":["osv","pip"],"epss":0.00579,"epssPercentile":0.46359,"ingestedAt":"2026-07-08T18:25:44.199Z","slug":"CVE-2025-54121","body":"## Overview\n\n### Summary\nWhen parsing a multi-part form with large files (greater than the [default max spool size](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/formparsers.py#L126)) `starlette` will block the main thread to roll the file over to disk. This blocks the event thread which means we can't accept new connections.\n\n### Details\nPlease see this discussion for details: https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403. In summary the following UploadFile code (copied from [here](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14)) has a minor bug. Instead of just checking for `self._in_memory` we should also check if the additional bytes will cause a rollover.\n\n```python\n\n    @property\n    def _in_memory(self) -> bool:\n        # check for SpooledTemporaryFile._rolled\n        rolled_to_disk = getattr(self.file, \"_rolled\", True)\n        return not rolled_to_disk\n\n    async def write(self, data: bytes) -> None:\n        if self.size is not None:\n            self.size += len(data)\n\n        if self._in_memory:\n            self.file.write(data)\n        else:\n            await run_in_threadpool(self.file.write, data)\n```\n\nI have already created a PR which fixes the problem: https://github.com/encode/starlette/pull/2962\n\n\n### PoC\nSee the discussion [here](https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403) for steps on how to reproduce.\n\n### Impact\nTo be honest, very low and not many users will be impacted. Parsing large forms is already CPU intensive so the additional IO block doesn't slow down `starlette` that much on systems with modern HDDs/SSDs. If someone is running on tape they might see a greater impact.\n\n## Affected packages\n\n- `starlette < 0.47.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `starlette 0.47.2`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}