Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1358
  • PyPI/fastapi-api-key
FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection 07 Jul
  • Fix available
  • Severity - 3.7 (Low)
PYSEC-2026-1363
  • PyPI/fastapi-users
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO 07 Jul
  • Fix available
  • Severity - 5.9 (Medium)
PYSEC-2026-1362
  • PyPI/fastapi-sso
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation 07 Jul
  • Fix available
  • Severity - 5.4 (Medium)
PYSEC-2026-1360
  • PyPI/fastapi-guard
FastAPI Guard has a regex bypass 07 Jul
  • Fix available
  • Severity - 7.8 (High)
PYSEC-2026-1359
  • PyPI/fastapi-guard
fastapi-guard is vulnerable to ReDoS through inefficient regex 07 Jul
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2026-1357
  • PyPI/fastapi-admin
FastAPI Admin Cross-site Scripting vulnerability in the Config-Create function 07 Jul
  • No fix available
  • Severity - 5.1 (Medium)
PYSEC-2026-1356
  • PyPI/fastapi-admin
FastAPI Admin cross-site scripting (XSS) vulnerability in the Create Product function 07 Jul
  • No fix available
  • Severity - 5.1 (Medium)
PYSEC-2026-1361
  • PyPI/fastapi-opa
OpaMiddleware does not filter HTTP OPTIONS requests 07 Jul
  • Fix available
  • Severity - 6.9 (Medium)
MAL-2026-1422
  • PyPI/fastapi-middleware-cors
Malicious code in fastapi-middleware-cors (PyPI) 13 Mar
  • No fix available
MAL-2026-1261
  • PyPI/fastapi-requests
Malicious code in fastapi-requests (PyPI) 06 Mar
  • No fix available
GHSA-95c6-p277-p87g
  • PyPI/fastapi-api-key
FastAPI Api Key has a timing side-channel in verify_key that allows statistical key validity detection 21 Jan
  • Fix available
  • Severity - 3.7 (Low)
GHSA-5j53-63w8-8625
  • PyPI/fastapi-users
FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO 19 Dec 2025
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-hp6r-r9vc-q8wx
  • PyPI/fastapi-sso
FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation 19 Dec 2025
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-rrf6-pxg8-684g
  • PyPI/fastapi-guard
FastAPI Guard has a regex bypass 23 Jul 2025
  • Fix available
  • Severity - 7.8 (High)
GHSA-j47q-rc62-w448
  • PyPI/fastapi-guard
fastapi-guard is vulnerable to ReDoS through inefficient regex 07 Jul 2025
  • Fix available
  • Severity - 6.9 (Medium)
PYSEC-2025-242
  • PyPI/fastapi-guard
See record for full details 06 May 2025
  • Fix available
  • Severity - 7.5 (High)