Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-54283 Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource cons… Starlette 1.3.1+ Fix from $1,9502026-06-22 MEDIUM 5.3 CVE-2026-54282 Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.ur… Starlette 1.3.0+ Fix from $1,6002026-06-22 MEDIUM 5.3 CVE-2026-48817 Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lower… Starlette 1.1.0+ Fix from $1,6002026-06-17 HIGH 7.5 CVE-2026-48818 Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \… Starlette 1.1.0+ Fix from $1,9502026-06-17 MEDIUM 6.5 CVE-2026-48710 Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reco… Starlette 1.0.1+ Fix from $1,6002026-05-26 HIGH 7.5 CVE-2023-29159 Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files i… Starlette 0.27.0+ Fix from $1,9502023-06-01 HIGH 7.5 CVE-2023-30798 There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify an… Starlette 0.25.0+ Fix from $1,9502023-04-21 CRITICAL 9.1 CVE-2021-41945 Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. Httpx 0.23.0+ Fix from $2,3002022-04-28 HIGH 7.5 CVE-2020-7694 This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever an… Uvicorn No fix yet Fix from $1,9502020-07-27 MEDIUM 5.3 CVE-2020-7695 Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit th… Uvicorn 0.11.7+ Fix from $1,6002020-07-27