Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
8 active CVEs reported via OSV.dev
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
Litestar has potential log injection in exception logging
Litestar and Starlite vulnerable to Path Traversal
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
Litestar allows unbounded resource consumption (DoS vulnerability)
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
Other Web Framework projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Litestar โ without relying on volunteer maintainers.
Talk to an Expert โ