Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242845
AlmaLinux
5975
Alpaquita
16181
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
771
Bitnami
9501
Chainguard
1048720
CleanStart
5479
CRAN
14
crates.io
2768
Debian
68994
Echo
7855
GHC
3
GIT
109121
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148659
npm
229272
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4354
Root
19655
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9977
Ubuntu
66090
VSCode
21
Wolfi
293843
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2603
PyPI/litestar
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
13 Jul
Fix available
Severity - 5.9 (Medium)
PYSEC-2026-2604
PyPI/litestar
Litestar has HTML Injection Through its CSRF Token
13 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-2605
PyPI/litestar
Litestar and Starlite vulnerable to Path Traversal
13 Jul
Fix available
Severity - 8.2 (High)
PYSEC-2026-1553
PyPI/litestar
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
07 Jul
Fix available
Severity - 7.5 (High)
GHSA-3qmc-cj7q-62hv
PyPI/litestar
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
10 Jun
Fix available
Severity - 5.9 (Medium)
GHSA-542p-wvx7-72m4
PyPI/litestar
Litestar has HTML Injection Through its CSRF Token
10 Jun
Fix available
Severity - 8.1 (High)
PYSEC-2026-2197
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-2196
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-2195
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-vxqx-rh46-q2pg
PyPI/litestar
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-93ph-p7v4-hwh4
PyPI/litestar
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-2p2x-hpg8-cqp2
PyPI/litestar
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
09 Feb
Fix available
Severity - 7.4 (High)
GHSA-hm36-ffrh-c77c
PyPI/litestar
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
06 Oct 2025
Fix available
Severity - 7.5 (High)
GHSA-674p-xv2x-rf3g
PyPI/litestar
Litestar has potential log injection in exception logging
11 Aug 2025
Fix available
Severity - 3.7 (Low)
GHSA-gjcc-jvgw-wvwj
PyPI/litestar
PyPI/starlite
Litestar allows unbounded resource consumption (DoS vulnerability)
20 Nov 2024
Fix available
Severity - 8.2 (High)
PYSEC-2024-178
PyPI/litestar
github.com/litestar-org/litestar
See record for full details
20 Nov 2024
Fix available
Severity - 7.5 (High)
Load more...
PyPI - OSV