23 Total advisories
23 Vulnerabilities
0 Malware

Dependency scanning

Check whether starlette is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
PyPI

CVE-2026-54283

Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS

MEDIUM 6.5
PyPI KEV

CVE-2026-48710

Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

HIGH 7.5
PyPI

CVE-2026-48818

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

LOW 3.7
PyPI

CVE-2026-54282

Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

HIGH 7.5
PyPI

CVE-2025-62727

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

MEDIUM 5.3
PyPI

CVE-2025-54121

Starlette has possible denial-of-service vector when parsing large files in multipart forms

NONE 0.0
PyPI

CVE-2024-47874

Starlette Denial of service (DoS) via multipart/form-data

MEDIUM 5.3
PyPI

CVE-2026-48817

Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

HIGH 7.5
PyPI

GHSA-93gm-qmq6-w238

Duplicate Advisory: Starlette Content-Type Header ReDoS

MEDIUM 5.3
PyPI

CVE-2026-48817

CVE-2026-48817

HIGH 7.5
PyPI

CVE-2026-48818

CVE-2026-48818

LOW 3.7
PyPI

CVE-2023-29159

Starlette has Path Traversal vulnerability in StaticFiles

HIGH 7.5
PyPI

CVE-2023-30798

MultipartParser denial of service with too many fields or files

HIGH 7.5
PyPI

CVE-2025-62727

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

NONE 0.0
PyPI

CVE-2024-47874

Starlette Denial of service (DoS) via multipart/form-data

MEDIUM 5.3
PyPI

CVE-2025-54121

Starlette has possible denial-of-service vector when parsing large files in multipart forms

HIGH 7.5
PyPI

CVE-2026-54283

CVE-2026-54283

MEDIUM 5.3
PyPI

CVE-2026-54282

CVE-2026-54282

UNKNOWN
PyPI

CVE-2026-48710

BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks

HIGH 7.5
PyPI

GHSA-qj8w-rv5x-2v9h

Duplicate Advisory: Starlette vulnerable to directory traversal

HIGH 7.5
PyPI

GHSA-3qj8-93xh-pwh2

Duplicate Advisory: Starlette allows an unauthenticated and remote attacker to specify any number of form fields or files

UNKNOWN
PyPI

CVE-2023-30798

CVE-2023-30798

UNKNOWN
PyPI

CVE-2023-29159

CVE-2023-29159

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes