VendorsEncodestarletteany version
Vulnerabilities

Encode Starlette any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2023-29159
Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.
Published 2023-06-01 · Modified
7.5EPSS 0.020
CVE-2024-24762
python-multipart vulnerable to content-type header Regular expression Denial of Service
Published 2024-02-05 · Analyzed
7.5EPSS 0.015
CVE-2023-30798
MultipartParser DOS with too many fields or files in Starlette Framework
Published 2023-04-21 · Modified
7.5EPSS 0.013
CVE-2026-54283
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
Published 2026-06-22 · Analyzed
7.5EPSS 0.004
CVE-2026-48818
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
Published 2026-06-17 · Modified
7.5EPSS 0.004
CVE-2026-48710
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Published 2026-05-26 · Analyzed
6.5KEVEPSS 0.363
CVE-2026-48817
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
Published 2026-06-17 · Analyzed
5.3EPSS 0.002
CVE-2026-54282
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Published 2026-06-22 · Analyzed
5.3EPSS 0.002