---
id: CVE-2026-54283
title: >-
  starlette: Starlette: request.form() limits silently ignored for
  application/x-www-form-urlencoded enable DoS (CVE-2026-54283)
summary: >-
  A flaw was found in Starlette where the request.form() method silently ignores
  configured resource limits (max_fields and max_part_size) when parsing
  application/x-www-form-urlencoded data. An unauthenticated attacker can
  exploit this by s…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-770
vendor: Red Hat
product: Red Hat OpenShift AI 3.4
affected:
  - exploit_intelligence
  - openshift_lightspeed
  - ai_inference_server
  - ansible_automation_platform 2
  - enterprise_linux_ai_rhel_ai 3
  - openshift_ai_rhoai
  - openshift_virtualization 4
  - ai_inference_server 3.2
  - ai_inference_server 3.4
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - migration_toolkit_for_applications 8.2
  - openshift_ai 3.4
  - satellite 6.17
patched:
  - ai_inference_server 3.2
  - ai_inference_server 3.4
  - ansible_automation_platform 2.6
  - ansible_automation_platform 2.7
  - migration_toolkit_for_applications 8.2
  - openshift_ai 3.4
  - satellite 6.17
published: '2026-06-22'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T05:56:06+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54283.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54283.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54283'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2491440'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-54283'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54283'
  - url: >-
      https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq
  - url: 'https://access.redhat.com/errata/RHSA-2026:61627'
  - url: 'https://access.redhat.com/errata/RHSA-2026:36005'
  - url: 'https://access.redhat.com/errata/RHSA-2026:36006'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70965'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70979'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70995'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69469'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70969'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50479'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42132'
  - url: 'https://access.redhat.com/errata/RHSA-2026:50340'
  - url: 'https://access.redhat.com/errata/RHSA-2026:42142'
  - url: 'https://access.redhat.com/errata/RHSA-2026:43038'
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
  - url: 'https://access.redhat.com/errata/RHSA-2026:44696'
  - url: 'https://github.com/Kludex/starlette'
  - url: 'https://github.com/advisories/GHSA-82w8-qh3p-5jfq'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
  - ghsa
epss: 0.00481
epssPercentile: 0.38865
aliases:
  - GHSA-82w8-qh3p-5jfq
  - PYSEC-2026-249
ecosystem: pip
ingestedAt: '2026-07-07T15:41:58.607Z'
---

## Overview

A flaw was found in Starlette where the request.form() method silently ignores configured resource limits (max_fields and max_part_size) when parsing application/x-www-form-urlencoded data. An unauthenticated attacker can exploit this by sending a urlencoded request body with an arbitrarily large number of fields or an oversized field, causing denial of service through resource exhaustion.

## Vendor advisories

- **RHSA-2026:61627** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61627)
- **RHSA-2026:36005** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:36005)
- **RHSA-2026:36006** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:36006)
- **RHSA-2026:69466** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69466)
- **RHSA-2026:70965** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70965)
- **RHSA-2026:70979** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70979)
- **RHSA-2026:69467** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69467)
- **RHSA-2026:70995** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70995)
- **RHSA-2026:69469** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69469)
- **RHSA-2026:70969** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70969)
- **RHSA-2026:69464** · Red Hat · fixed in: Red Hat AI Inference Server 3.4 · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69464)
- **Red Hat VEX** · Important · affected: Exploit Intelligence, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI), … · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Exploit Intelligence, OpenShift Lightspeed, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54283.json)
- **RHSA-2026:50479** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50479)
- **RHSA-2026:42132** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42132)
- **RHSA-2026:50340** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50340)
- **RHSA-2026:42142** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.7 · released 2026-07-20 · [advisory](https://access.redhat.com/errata/RHSA-2026:42142)

**starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS** — rated Important by Red Hat. Released 2026-06-22, updated 2026-09-24.

Affected:

- Exploit Intelligence
- OpenShift Lightspeed
- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Virtualization 4

Fixed:

- Red Hat AI Inference Server 3.2
- Red Hat AI Inference Server 3.4
- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Migration Toolkit for Applications 8.2
- Red Hat OpenShift AI 3.4
- Red Hat Satellite 6.17

No fix planned:

- Red Hat AI Inference Server
- Red Hat Ansible Automation Platform 2
- Exploit Intelligence
- OpenShift Lightspeed
- Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat OpenShift AI (RHOAI)
- Red Hat OpenShift Virtualization 4

Not affected:

- Red Hat Ansible Automation Platform 2.6
- Red Hat Ansible Automation Platform 2.7
- Red Hat Migration Toolkit for Applications 8.2
- Red Hat OpenShift AI 3.4
- OpenShift Lightspeed
- Red Hat Enterprise Linux command line assistant
- Red Hat Hardened Images
- Red Hat OpenShift AI (RHOAI)
- Red Hat Satellite 6

## Remediation

For more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627
For more information visit https://access.redhat.com/errata/RHSA-2026:36005 https://access.redhat.com/errata/RHSA-2026:36005
For more information visit https://access.redhat.com/errata/RHSA-2026:36006 https://access.redhat.com/errata/RHSA-2026:36006

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2026-54283)

Affected packages:

- `starlette >= 0.4.1, < 1.3.1`

Patched in:

- `starlette 1.3.1`

Source: https://osv.dev/vulnerability/GHSA-82w8-qh3p-5jfq
