---
id: CVE-2025-54121
aliases:
  - GHSA-2c2j-9gv5-cj73
  - PYSEC-2026-1941
title: >-
  Starlette has possible denial-of-service vector when parsing large files in
  multipart forms
summary: >-
  Starlette has possible denial-of-service vector when parsing large files in
  multipart forms
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
vendor: starlette
product: starlette
ecosystem: pip
affected:
  - starlette < 0.47.2
patched:
  - starlette 0.47.2
published: '2025-07-21'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:25.704876348Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-2c2j-9gv5-cj73'
references:
  - url: >-
      https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54121'
  - url: >-
      https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1
  - url: 'https://github.com/encode/starlette'
  - url: >-
      https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14
  - url: >-
      https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403
tags:
  - osv
  - pip
epss: 0.00579
epssPercentile: 0.45241
ingestedAt: '2026-07-08T18:25:44.199Z'
---

## Overview

### Summary
When parsing a multi-part form with large files (greater than the [default max spool size](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/formparsers.py#L126)) `starlette` will block the main thread to roll the file over to disk. This blocks the event thread which means we can't accept new connections.

### Details
Please see this discussion for details: https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403. In summary the following UploadFile code (copied from [here](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14)) has a minor bug. Instead of just checking for `self._in_memory` we should also check if the additional bytes will cause a rollover.

```python

    @property
    def _in_memory(self) -> bool:
        # check for SpooledTemporaryFile._rolled
        rolled_to_disk = getattr(self.file, "_rolled", True)
        return not rolled_to_disk

    async def write(self, data: bytes) -> None:
        if self.size is not None:
            self.size += len(data)

        if self._in_memory:
            self.file.write(data)
        else:
            await run_in_threadpool(self.file.write, data)
```

I have already created a PR which fixes the problem: https://github.com/encode/starlette/pull/2962


### PoC
See the discussion [here](https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403) for steps on how to reproduce.

### Impact
To be honest, very low and not many users will be impacted. Parsing large forms is already CPU intensive so the additional IO block doesn't slow down `starlette` that much on systems with modern HDDs/SSDs. If someone is running on tape they might see a greater impact.

## Affected packages

- `starlette < 0.47.2`

## Remediation

Upgrade to a patched release:

- `starlette 0.47.2`
