Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2603
  • PyPI/litestar
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header 13 Jul
  • Fix available
  • Severity - 5.9 (Medium)
PYSEC-2026-2604
  • PyPI/litestar
Litestar has HTML Injection Through its CSRF Token 13 Jul
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-2605
  • PyPI/litestar
Litestar and Starlite vulnerable to Path Traversal 13 Jul
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-1553
  • PyPI/litestar
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion 07 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-3qmc-cj7q-62hv
  • PyPI/litestar
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header 10 Jun
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-542p-wvx7-72m4
  • PyPI/litestar
Litestar has HTML Injection Through its CSRF Token 10 Jun
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-2197
  • PyPI/litestar
See record for full details 09 Feb
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-2196
  • PyPI/litestar
See record for full details 09 Feb
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-2195
  • PyPI/litestar
See record for full details 09 Feb
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-vxqx-rh46-q2pg
  • PyPI/litestar
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD) 09 Feb
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-93ph-p7v4-hwh4
  • PyPI/litestar
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns 09 Feb
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-2p2x-hpg8-cqp2
  • PyPI/litestar
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins 09 Feb
  • Fix available
  • Severity - 7.4 (High)
GHSA-hm36-ffrh-c77c
  • PyPI/litestar
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion 06 Oct 2025
  • Fix available
  • Severity - 7.5 (High)
GHSA-674p-xv2x-rf3g
  • PyPI/litestar
Litestar has potential log injection in exception logging 11 Aug 2025
  • Fix available
  • Severity - 3.7 (Low)
GHSA-gjcc-jvgw-wvwj
  • PyPI/litestar
  • PyPI/starlite
Litestar allows unbounded resource consumption (DoS vulnerability) 20 Nov 2024
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2024-178
  • PyPI/litestar
  • github.com/litestar-org/litestar
See record for full details 20 Nov 2024
  • Fix available
  • Severity - 7.5 (High)