Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-06-29
10 active CVEs reported via OSV.dev
Starlette has possible denial-of-service vector when parsing large files in multipart forms
MultipartParser denial of service with too many fields or files
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Starlette Denial of service (DoS) via multipart/form-data
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Starlette has Path Traversal vulnerability in StaticFiles
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
Get SLA-backed support, security patches, and direct access to senior engineers for Starlette — without relying on volunteer maintainers.