Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3924
  • PyPI/starlette-admin
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS 10 Sep
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-6753-gr46-6wpr
  • PyPI/starlette-admin
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS 26 Aug
  • Fix available
  • Severity - 5.4 (Medium)
PYSEC-2026-1942
  • PyPI/starlette
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse`` 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1941
  • PyPI/starlette
Starlette has possible denial-of-service vector when parsing large files in multipart forms 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1943
  • PyPI/starlette
Starlette Denial of service (DoS) via multipart/form-data 07 Jul
  • Fix available
  • Severity - 8.7 (High)
MAL-2026-6724
  • PyPI/starlette-healthcheck
Malicious code in starlette-healthcheck (PyPI) 01 Jul
  • No fix available
PYSEC-2026-249
  • PyPI/starlette
See record for full details 22 Jun
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-248
  • PyPI/starlette
See record for full details 22 Jun
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2280
  • PyPI/starlette
See record for full details 17 Jun
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-2281
  • PyPI/starlette
See record for full details 17 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-82w8-qh3p-5jfq
  • PyPI/starlette
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS 15 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-jp82-jpqv-5vv3
  • PyPI/starlette
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname 15 Jun
  • Fix available
  • Severity - 3.7 (Low)
GHSA-wqp7-x3pw-xc5r
  • PyPI/starlette
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows 15 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-x746-7m8f-x49c
  • PyPI/starlette
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr` 15 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-86qp-5c8j-p5mr
  • PyPI/starlette
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks 04 Jun
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-161
  • PyPI/starlette
BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks 22 May
  • Fix available