VulnSea

starlette vulnerabilities

CVEs whose affected-version data names the starlette package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-48817Medium· 5.3
3mo ago

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

Sunlitstarlette · starletteEPSS 0.21%via OSV
CVE-2026-48818High· 7.5
3mo ago

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

Twilightstarlette · starletteEPSS 0.37%via OSV
CVE-2026-54282Low· 3.7
3mo ago

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Sunlitstarlette · starletteEPSS 0.19%via OSV
CVE-2026-48710Medium· 6.5CISA KEVPoC
3mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

Midnightstarlette · starletteEPSS 36%via NVD
CVE-2025-62727High· 7.5PoC
10mo ago

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Midnightstarlette · starletteEPSS 0.64%via OSV
CVE-2025-54121Medium· 5.3
1y ago

Starlette has possible denial-of-service vector when parsing large files in multipart forms

Starlette has possible denial-of-service vector when parsing large files in multipart forms

Sunlitstarlette · starletteEPSS 0.58%via OSV
CVE-2024-47874None· 0.0
1y ago

Starlette Denial of service (DoS) via multipart/form-data

Starlette Denial of service (DoS) via multipart/form-data

Sunlitstarlette · starletteEPSS 0.65%via OSV
CVE-2023-29159Low· 3.7
3y ago

Starlette has Path Traversal vulnerability in StaticFiles

Starlette has Path Traversal vulnerability in StaticFiles

Sunlitstarlette · starletteEPSS 2.0%via OSV
CVE-2023-30798High· 7.5
3y ago

MultipartParser denial of service with too many fields or files

MultipartParser denial of service with too many fields or files

Twilightstarlette · starletteEPSS 1.3%via OSV
starlette vulnerabilities (CVEs) · VulnSea