Dependency scanning
Check whether starlette is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-54283
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
CVE-2026-48710
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
CVE-2026-48818
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
CVE-2026-54282
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVE-2025-62727
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
CVE-2025-54121
Starlette has possible denial-of-service vector when parsing large files in multipart forms
CVE-2024-47874
Starlette Denial of service (DoS) via multipart/form-data
CVE-2026-48817
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
GHSA-93gm-qmq6-w238
Duplicate Advisory: Starlette Content-Type Header ReDoS
CVE-2026-48817
CVE-2026-48817
CVE-2026-48818
CVE-2026-48818
CVE-2023-29159
Starlette has Path Traversal vulnerability in StaticFiles
CVE-2023-30798
MultipartParser denial of service with too many fields or files
CVE-2025-62727
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
CVE-2024-47874
Starlette Denial of service (DoS) via multipart/form-data
CVE-2025-54121
Starlette has possible denial-of-service vector when parsing large files in multipart forms
CVE-2026-54283
CVE-2026-54283
CVE-2026-54282
CVE-2026-54282
CVE-2026-48710
BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks
GHSA-qj8w-rv5x-2v9h
Duplicate Advisory: Starlette vulnerable to directory traversal
GHSA-3qj8-93xh-pwh2
Duplicate Advisory: Starlette allows an unauthenticated and remote attacker to specify any number of form fields or files
CVE-2023-30798
CVE-2023-30798
CVE-2023-29159
CVE-2023-29159
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes