Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2184176
AlmaLinux
5857
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17129
BellSoft Hardened Containers
744
Bitnami
9212
Chainguard
1019778
CleanStart
3432
CRAN
14
crates.io
2710
Debian
67341
Echo
6541
GHC
3
GIT
106316
GitHub Actions
55
Go
9147
Hackage
32
Hex
351
Julia
1713
Linux
29368
Mageia
6200
Maven
6998
MinimOS
142693
npm
228436
NuGet
1860
opam
29
openEuler
8541
openSUSE
14325
OSS-Fuzz
4003
Packagist
7036
Pub
11
PyPI
25074
Red Hat
23028
Rocky Linux
4229
Root
19463
RubyGems
4709
SUSE
23039
SwiftURL
59
TuxCare
9199
Ubuntu
64326
VSCode
21
Wolfi
287370
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2603
PyPI/litestar
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
13 Jul
Fix available
Severity - 5.9 (Medium)
PYSEC-2026-2604
PyPI/litestar
Litestar has HTML Injection Through its CSRF Token
13 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-2605
PyPI/litestar
Litestar and Starlite vulnerable to Path Traversal
13 Jul
Fix available
Severity - 8.2 (High)
PYSEC-2026-1553
PyPI/litestar
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
07 Jul
Fix available
Severity - 7.5 (High)
GHSA-3qmc-cj7q-62hv
PyPI/litestar
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
10 Jun
Fix available
Severity - 5.9 (Medium)
GHSA-542p-wvx7-72m4
PyPI/litestar
Litestar has HTML Injection Through its CSRF Token
10 Jun
Fix available
Severity - 8.1 (High)
PYSEC-2026-2197
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-2196
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
PYSEC-2026-2195
PyPI/litestar
See record for full details
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-vxqx-rh46-q2pg
PyPI/litestar
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-93ph-p7v4-hwh4
PyPI/litestar
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
09 Feb
Fix available
Severity - 6.5 (Medium)
GHSA-2p2x-hpg8-cqp2
PyPI/litestar
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
09 Feb
Fix available
Severity - 7.4 (High)
GHSA-hm36-ffrh-c77c
PyPI/litestar
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
06 Oct 2025
Fix available
Severity - 7.5 (High)
GHSA-674p-xv2x-rf3g
PyPI/litestar
Litestar has potential log injection in exception logging
11 Aug 2025
Fix available
Severity - 3.7 (Low)
GHSA-gjcc-jvgw-wvwj
PyPI/litestar
PyPI/starlite
Litestar allows unbounded resource consumption (DoS vulnerability)
20 Nov 2024
Fix available
Severity - 8.2 (High)
PYSEC-2024-178
PyPI/litestar
github.com/litestar-org/litestar
See record for full details
20 Nov 2024
Fix available
Severity - 7.5 (High)
Load more...
PyPI - OSV