Encode
Encode Starlette: vulnerabilities and CVEs
Encode Starlette has 13 published vulnerabilities, 8 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.
CVEs13
Last 12 months8
Critical0
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48710 | Medium (6.5) | 7.1% | ⚠ Active exploitation | May 26, 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54553 | Medium (5.4) | 0.45% | — | Aug 26, 2026 | Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applications. Prior to 0.16.1, the list API does not validate user-supplied order_by and structured where… |
| CVE-2026-54283 | High (7.5) | 0.48% | — | Jun 22, 2026 | Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for… |
| CVE-2026-54282 | Medium (5.3) | 0.27% | — | Jun 22, 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating… |
| CVE-2026-48817 | Medium (5.3) | 0.35% | — | Jun 17, 2026 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr,… |
| CVE-2026-48818 | High (7.5) | 0.65% | — | Jun 17, 2026 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to initiate an outbound… |
| CVE-2026-45554 | Medium (5.3) | 0.60% | — | Jun 2, 2026 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rather than a file.… |
| CVE-2026-48710 | Medium (6.5) | 7.1% | ⚠ Active exploitation | May 26, 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw… |
| CVE-2025-62727 | High (7.5) | 0.68% | — | Oct 28, 2025 | Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in… |
| CVE-2025-54121 | Medium (5.3) | 0.58% | — | Jul 21, 2025 | Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large… |
| CVE-2025-0182 | High (7.5) | 0.70% | — | Mar 20, 2025 | A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of the starlette package (<=0.49) via fastapi, which was… |
| CVE-2024-47874 | High (8.7) | 0.65% | — | Oct 15, 2024 | Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and buffers those in byte… |
| CVE-2023-29159 | High (7.5) | 2.0% | — | Jun 1, 2023 | Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette. |
| CVE-2023-30798 | High (7.5) | 1.3% | — | Apr 21, 2023 | There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.