CVE-2026-54283High· 7.5▾ TwilightA flaw was found in Starlette where the request.form() method silently ignores configured resource limits (max_fields and max_part_size) when parsing application/x-www-form-urlencoded data. An unauthenticated attacker can exploit this by s…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.3%
0.3% → 0.5%
Last analysed / modified upstream
A flaw was found in Starlette where the request.form() method silently ignores configured resource limits (max_fields and max_part_size) when parsing application/x-www-form-urlencoded data. An unauthenticated attacker can exploit this by sending a urlencoded request body with an arbitrarily large number of fields or an oversized field, causing denial of service through resource exhaustion.
starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS — rated Important by Red Hat. Released 2026-06-22, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
For more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627 For more information visit https://access.redhat.com/errata/RHSA-2026:36005 https://access.redhat.com/errata/RHSA-2026:36005 For more information visit https://access.redhat.com/errata/RHSA-2026:36006 https://access.redhat.com/errata/RHSA-2026:36006
Workarounds / mitigations:
Affected packages:
starlette >= 0.4.1, < 1.3.1Patched in:
starlette 1.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59200High· 7.5Pillow: Pillow: Denial of service via crafted PDF stream (CVE-2026-59200)
CVE-2026-59204High· 7.5Pillow: Pillow: Denial of Service via crafted JPEG2000 image (CVE-2026-59204)
CVE-2026-55379High· 7.5python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379)
CVE-2026-59197High· 8.2Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
CVE-2026-54058Critical· 9.1Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)
CVE-2026-59205High· 7.5Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API (CVE-2026-59205)