Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Starlette HIGH 7.5
CVE-2026-54283

Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource cons…

Fix: 1.3.1+
Fix from $1,950 2026-06-22
Starlette MEDIUM 5.3
CVE-2026-54282

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.ur…

Fix: 1.3.0+
Fix from $1,600 2026-06-22
Starlette MEDIUM 5.3
CVE-2026-48817

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lower…

Fix: 1.1.0+
Fix from $1,600 2026-06-17
Starlette HIGH 7.5
CVE-2026-48818

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \…

Fix: 1.1.0+
Fix from $1,950 2026-06-17
Starlette MEDIUM 6.5
CVE-2026-48710

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reco…

Fix: 1.0.1+
Fix from $1,600 2026-05-26
Starlette HIGH 7.5
CVE-2023-29159

Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files i…

Fix: 0.27.0+
Fix from $1,950 2023-06-01
Starlette HIGH 7.5
CVE-2023-30798

There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify an…

Fix: 0.25.0+
Fix from $1,950 2023-04-21
Httpx CRITICAL 9.1
CVE-2021-41945

Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.

Fix: 0.23.0+
Fix from $2,300 2022-04-28
Uvicorn HIGH 7.5
CVE-2020-7694

This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever an…

No fix yet
Fix from $1,950 2020-07-27
Uvicorn MEDIUM 5.3
CVE-2020-7695

Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit th…

Fix: 0.11.7+
Fix from $1,600 2020-07-27