Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2198799
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3674
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9290
Chainguard
1023665
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68367
Echo
6721
GHC
3
GIT
108079
GitHub Actions
55
Go
9203
Hackage
32
Hex
361
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144358
npm
228732
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25166
Red Hat
23331
Rocky Linux
4295
Root
19534
RubyGems
5326
SUSE
23168
SwiftURL
60
TuxCare
9498
Ubuntu
65370
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2603
PyPI/litestar
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
13 Jul
Fix available
Severity - 5.9 (Medium)
PYSEC-2026-2604
PyPI/litestar
Litestar has HTML Injection Through its CSRF Token
13 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-2605
PyPI/litestar
Litestar and Starlite vulnerable to Path Traversal
13 Jul
Fix available
Severity - 8.2 (High)
PYSEC-2026-1553
PyPI/litestar
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
07 Jul
Fix available
Severity - 7.5 (High)
GHSA-3qmc-cj7q-62hv
PyPI/litestar
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
10 Jun
Fix available
Severity - 5.9 (Medium)
GHSA-542p-wvx7-72m4
PyPI/litestar
Litestar has HTML Injection Through its CSRF Token
10 Jun
Fix available
Severity - 8.1 (High)
PYSEC-2026-2197
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-2196
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-2195
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-vxqx-rh46-q2pg
PyPI/litestar
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-93ph-p7v4-hwh4
PyPI/litestar
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-2p2x-hpg8-cqp2
PyPI/litestar
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
09 Feb
Fix available
Severity - 7.4 (High)
GHSA-hm36-ffrh-c77c
PyPI/litestar
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
06 Oct 2025
Fix available
Severity - 7.5 (High)
GHSA-674p-xv2x-rf3g
PyPI/litestar
Litestar has potential log injection in exception logging
11 Aug 2025
Fix available
Severity - 3.7 (Low)
GHSA-gjcc-jvgw-wvwj
PyPI/litestar
PyPI/starlite
Litestar allows unbounded resource consumption (DoS vulnerability)
20 Nov 2024
Fix available
Severity - 8.2 (High)
PYSEC-2024-178
PyPI/litestar
github.com/litestar-org/litestar
See record for full details
20 Nov 2024
Fix available
Severity - 7.5 (High)
Load more...
PyPI - OSV