VulnSea

litestar has 8 CVEs on record between 2024 and 2026. 1 was published in the last 90 days. The busiest recent month was February 2026 with 3. The median CVSS is 7.5 (high). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
1 prev 1

Products

  • litestar 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

litestar vulnerabilities

CVEs affecting litestar, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-48061Medium· 5.9
1mo ago

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whiteli…

Sunlitlitestar · litestarEPSS 0.34%via NVD
CVE-2026-48060High· 8.1PoC
3mo ago

Litestar has HTML Injection Through its CSRF Token

Litestar has HTML Injection Through its CSRF Token

Midnightlitestar · litestarEPSS 0.28%via GHSA
CVE-2026-25480Medium· 6.5
7mo ago

Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

Sunlitlitestar · litestarEPSS 0.43%via OSV
CVE-2026-25479Medium· 6.5
7mo ago

Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns

Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns

Sunlitlitestar · litestarEPSS 0.33%via OSV
CVE-2026-25478High· 7.4
7mo ago

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

Twilightlitestar · litestarEPSS 0.40%via OSV
CVE-2025-59152High· 7.5
11mo ago

Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion

Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion

Twilightlitestar · litestarEPSS 0.48%via OSV
CVE-2024-52581High· 7.5
1y ago

Litestar allows unbounded resource consumption (DoS vulnerability)

Litestar allows unbounded resource consumption (DoS vulnerability)

Twilightlitestar · litestarEPSS 0.79%via OSV
CVE-2024-32982High· 8.2
2y ago

Litestar and Starlite vulnerable to Path Traversal

Litestar and Starlite vulnerable to Path Traversal

Twilightlitestar · litestarEPSS 0.72%via OSV
litestar vulnerabilities (CVEs) · VulnSea