VulnSea

starlette has 9 CVEs on record between 2023 and 2026. The busiest recent month was June 2026 with 3. The median CVSS is 5.3 (medium). 11% have been exploited in the wild, in line with the corpus average.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
11% vs 1% corpus
Median CVSS
5.3
Publish → KEV
(1)
Last 90 days
0 prev 4

Products

  • starlette 9
9
Total CVEs
0
Critical
1
CISA KEV
1
Exploited

starlette vulnerabilities

CVEs affecting starlette, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-48817Medium· 5.3
3mo ago

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

Sunlitstarlette · starletteEPSS 0.21%via OSV
CVE-2026-48818High· 7.5
3mo ago

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

Twilightstarlette · starletteEPSS 0.37%via OSV
CVE-2026-54282Low· 3.7
3mo ago

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

Sunlitstarlette · starletteEPSS 0.19%via OSV
CVE-2026-48710Medium· 6.5CISA KEVPoC
3mo ago

Starlette is a lightweight ASGI framework/toolkit

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `…

Midnightstarlette · starletteEPSS 36%via NVD
CVE-2025-62727High· 7.5PoC
10mo ago

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Midnightstarlette · starletteEPSS 0.64%via OSV
CVE-2025-54121Medium· 5.3
1y ago

Starlette has possible denial-of-service vector when parsing large files in multipart forms

Starlette has possible denial-of-service vector when parsing large files in multipart forms

Sunlitstarlette · starletteEPSS 0.58%via OSV
CVE-2024-47874None· 0.0
1y ago

Starlette Denial of service (DoS) via multipart/form-data

Starlette Denial of service (DoS) via multipart/form-data

Sunlitstarlette · starletteEPSS 0.65%via OSV
CVE-2023-29159Low· 3.7
3y ago

Starlette has Path Traversal vulnerability in StaticFiles

Starlette has Path Traversal vulnerability in StaticFiles

Sunlitstarlette · starletteEPSS 2.0%via OSV
CVE-2023-30798High· 7.5
3y ago

MultipartParser denial of service with too many fields or files

MultipartParser denial of service with too many fields or files

Twilightstarlette · starletteEPSS 1.3%via OSV
starlette vulnerabilities (CVEs) · VulnSea