litestar has 8 CVEs on record between 2024 and 2026. 1 was published in the last 90 days. The busiest recent month was February 2026 with 3. The median CVSS is 7.5 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 1
Worst active — by depth score
CVE-2026-48060High· 8.1Litestar has HTML Injection Through its CSRF Token57CVE-2024-32982High· 8.2Litestar and Starlite vulnerable to Path Traversal45CVE-2026-25478High· 7.4Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins41CVE-2025-59152High· 7.5Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion41CVE-2024-52581High· 7.5Litestar allows unbounded resource consumption (DoS vulnerability) 41
litestar vulnerabilities
CVEs affecting litestar, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-48061Medium· 5.9Litestar is an Asynchronous Server Gateway Interface (ASGI) framework
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whiteli…
CVE-2026-48060High· 8.1PoCLitestar has HTML Injection Through its CSRF Token
Litestar has HTML Injection Through its CSRF Token
CVE-2026-25480Medium· 6.5Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
CVE-2026-25479Medium· 6.5Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
CVE-2026-25478High· 7.4Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
CVE-2025-59152High· 7.5Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
CVE-2024-52581High· 7.5Litestar allows unbounded resource consumption (DoS vulnerability)
Litestar allows unbounded resource consumption (DoS vulnerability)
CVE-2024-32982High· 8.2Litestar and Starlite vulnerable to Path Traversal
Litestar and Starlite vulnerable to Path Traversal