Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.65% | — | Forget-c Jellyfish AI Short Drama StudioAITiangolo FastapiAI | 18/9/2026 | 22/9/2026 | A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The… | |
| Aplazada | Alta (8.8) | 1.1% | — | MarkerAITiangolo FastapiAI | 4/9/2026 | 23/9/2026 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location or delete existing files on the system. | |
| Aplazada | Media (5.4) | 0.45% | — | Starlette AdminAITiangolo FastapiAIEncode StarletteAI | 26/8/2026 | 9/9/2026 | Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where field names against the configured sortable_fields and searchable_fields allowlists. An… | |
| Analizada | Baja (3.7) | 0.34% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a… | |
| Analizada | Alta (7.5) | 0.46% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to… | |
| Analizada | Baja (3.7) | 0.26% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator.… | |
| Analizada | Media (5.3) | 0.29% | — | Fastapiexpert Python-multipart | 22/6/2026 | 26/6/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the… | |
| Aplazada | Alta (8.7) | 0.81% | — | Hermes AgentAITiangolo FastapiAI | 17/6/2026 | 18/6/2026 | Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation. FastAPI HTTP middleware does not execute for WebSocket upgrade requests on /api/pty, /api/ws, /api/pub, and /api/events endpoints, enabling attackers to exploit… | |
| Aplazada | Media (5.4) | 0.23% | — | FastapiadminAI | 9/6/2026 | 23/7/2026 | A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a chat message. | |
| Aplazada | Media (6.1) | 0.25% | — | FastapiadminAI | 9/6/2026 | 23/7/2026 | A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the notice_content parameter. | |
| Aplazada | Media (6.5) | 0.41% | — | FastapiadminAI | 9/6/2026 | 23/7/2026 | An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:update permission to cause a Denial of Service (DoS) via manipulating the func field of scheduled tasks. | |
| Aplazada | Media (5.3) | 0.60% | — | Zauberzeug NiceguiAITiangolo FastapiAIEncode StarletteAIEncode UvicornAI | 2/6/2026 | 22/7/2026 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file. Requests that resolve to a directory raise an unhandled RuntimeError inside Starlette's FileResponse,… | |
| Analizada | Media (5.3) | 0.42% | — | Fastapiexpert Python-multipart | 18/4/2026 | 17/6/2026 | Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing… | |
| Aplazada | Baja (2.1) | 0.19% | — | Vanna-ai VannaAITiangolo FastapiAIPalletsprojects FlaskAI | 2/4/2026 | 17/6/2026 | A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the component FastAPI/Flask Server. Executing a manipulation can lead to permissive cross-domain policy with untrusted domains. The attack can be launched remotely. The exploit has been published and may be… | |
| Aplazada | Baja (2.1) | 0.35% | — | Dbgpt Db-gptAITiangolo FastapiAI | 20/3/2026 | 17/6/2026 | A vulnerability has been found in eosphoros-ai DB-GPT up to 0.7.5. This issue affects the function module_plugin.refresh_plugins of the file packages/dbgpt-serve/src/dbgpt_serve/agent/hub/controller.py of the component FastAPI Endpoint. Such manipulation leads to unrestricted upload. It is possible to launch the… | |
| Analizada | Baja (2.1) | 0.50% | — | Fastapiadmin | 23/2/2026 | 17/6/2026 | A flaw has been found in FastApiAdmin up to 2.2.0. This issue affects the function user_avatar_upload_controller of the file /backend/app/api/v1/module_system/user/controller.py of the component Scheduled Task API. Executing a manipulation can lead to unrestricted upload. The attack can be launched remotely. The… | |
| Analizada | Baja (2.1) | 0.50% | — | Fastapiadmin | 23/2/2026 | 17/6/2026 | A vulnerability was detected in FastApiAdmin up to 2.2.0. This vulnerability affects the function upload_file_controller of the file /backend/app/api/v1/module_system/params/controller.py of the component Scheduled Task API. Performing a manipulation results in unrestricted upload. The attack can be initiated… | |
| Analizada | Baja (2.1) | 0.50% | — | Fastapiadmin | 23/2/2026 | 17/6/2026 | A security vulnerability has been detected in FastApiAdmin up to 2.2.0. This affects the function upload_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Scheduled Task API. Such manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.50% | — | Fastapiadmin | 23/2/2026 | 17/6/2026 | A weakness has been identified in FastApiAdmin up to 2.2.0. Affected by this issue is the function download_controller of the file /backend/app/api/v1/module_common/file/controller.py of the component Download Endpoint. This manipulation of the argument file_path causes information disclosure. It is possible to… | |
| Analizada | Media (5.5) | 0.64% | — | Fastapiadmin | 23/2/2026 | 17/6/2026 | A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/app/plugin/init_app.py of the component Custom Documentation Endpoint. The manipulation results in information disclosure. The attack may be performed from remote. The… | |
| Modificada | Alta (7.5) | 2.2% | — | Fastapiexpert Python-multipart | 27/1/2026 | 7/8/2026 | Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious… | |
| Analizada | Baja (3.7) | 0.30% | — | Athroniaeth Fastapi API KEY | 21/1/2026 | 17/6/2026 | FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-channel vulnerability in verify_key(). The method applied a random delay only on verification failures, allowing an attacker to statistically distinguish valid from invalid API keys by measuring… | |
| Analizada | Alta (8.8) | 0.26% | — | Fastapi-users Project Fastapi Users | 19/12/2025 | 17/6/2026 | FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow.… | |
| Aplazada | Media (5.4) | 0.36% | — | Fastapi-ssoAI | 19/12/2025 | 17/6/2026 | Versions of the package fastapi-sso before 0.19.0 are vulnerable to Cross-site Request Forgery (CSRF) due to the improper validation of the OAuth state parameter during the authentication callback. While the get_login_url method allows for state generation, it does not persist the state or bind it to the user's… | |
| Analizada | Alta (7.8) | 0.76% | — | Fastapi-guard Fastapi Guard | 23/7/2025 | 17/6/2026 | fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular expression patched to mitigate the ReDoS vulnerability by limiting the length of string fails to catch inputs that exceed this limit. This type of… |