18 Total advisories
18 Vulnerabilities
0 Malware
Vulnerabilities
HIGH 7.5
CVE-2026-54283
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
LOW 3.7
CVE-2026-54282
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
HIGH 7.5
CVE-2026-54283
CVE-2026-54283
MEDIUM 5.3
CVE-2026-54282
CVE-2026-54282
MEDIUM 5.3
CVE-2026-48817
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
HIGH 7.5
CVE-2026-48818
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
MEDIUM 6.5
CVE-2026-48710
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
UNKNOWN
CVE-2026-48710
BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks
HIGH 7.5
CVE-2025-62727
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
HIGH 7.5
CVE-2023-30798
MultipartParser denial of service with too many fields or files
LOW 3.7
CVE-2023-29159
Starlette has Path Traversal vulnerability in StaticFiles
MEDIUM 5.3
CVE-2025-54121
Starlette has possible denial-of-service vector when parsing large files in multipart forms
HIGH 7.5
GHSA-93gm-qmq6-w238
Duplicate Advisory: Starlette Content-Type Header ReDoS
NONE 0.0
CVE-2024-47874
Starlette Denial of service (DoS) via multipart/form-data
HIGH 7.5
GHSA-qj8w-rv5x-2v9h
Duplicate Advisory: Starlette vulnerable to directory traversal
HIGH 7.5
GHSA-3qj8-93xh-pwh2
Duplicate Advisory: Starlette allows an unauthenticated and remote attacker to specify any number of form fields or files
UNKNOWN
CVE-2023-30798
CVE-2023-30798
UNKNOWN
CVE-2023-29159
CVE-2023-29159
Ready to move
Start Securing
Free, no credit card | First findings in minutes