OSS Support Hub / Web Framework

Python Web Framework MIT Latest: v2.24.0

Litestar

Flexible, lightweight ASGI framework for building high-performance APIs with Python

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

8.3K+56
GitHub Stars
📦
v2.24.0
Latest Release · 18 days ago
🔄
45d
Avg. Release Cadence
🐛
286
Open Issues
📅
Yesterday
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins

Published: 2026-02-09 Fixed in: 2.20.0

Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header

Published: 2026-06-10 Fixed in: 2.22.0

Litestar has HTML Injection Through its CSRF Token

Published: 2026-06-10 Fixed in: 2.22.0

Litestar has potential log injection in exception logging

Published: 2025-08-11 Fixed in: 2.17.0

Litestar and Starlite vulnerable to Path Traversal

Published: 2024-05-06 Fixed in: 2.8.3

Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns

Published: 2026-02-09 Fixed in: 2.20.0

Litestar allows unbounded resource consumption (DoS vulnerability)

Published: 2024-11-20 Fixed in: 2.13.0

Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion

Published: 2025-10-06 Fixed in: 2.18.0

Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)

Published: 2026-02-09 Fixed in: 2.20.0
PYSEC-2024-178 CVSS_V3

Published: 2024-11-20 Fixed in: 53c1473b5ff7502816a9a339ffc90731bb0c2138

Alternatives to Litestar

Other Web Framework projects in the Python ecosystem worth evaluating.

Support Options for Litestar

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Litestar — without relying on volunteer maintainers.