---
schema_version: '1.0'
id: security-20260711-cd40e8
url: https://osv.dev/vulnerability/GHSA-2c2j-9gv5-cj73
url_hash: cd40e85870ffcd67a5511611e903256e4e67884e0ff557844036d81bfe71cba4
canonical_url: https://osv.dev/vulnerability/GHSA-2c2j-9gv5-cj73
source: osv:ghsa
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2025-54121
- GHSA-2c2j-9gv5-cj73
- severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- starlette
- PyPI
lang: en
published_at: '2025-07-21T19:34:23Z'
fetched_at: '2026-07-11T06:37:18Z'
updated_at: '2026-07-11T06:39:54Z'
status: published
content_hash: 822701881c9a73e20810a49be25ab3bac172e03ca14809edaad4f45e50a90727
license_note: full
summary: Starlette has possible denial-of-service vector when parsing large files
  in multipart forms
summary_source: rss
summary_en: Starlette has possible denial-of-service vector when parsing large files
  in multipart forms
entities:
- name: HashTag
  type: concept
key_facts: []
related: []
related_auto:
- name: SustainableQuantumComputing
  type: concept
  weight: 3.0
title: 'CVE-2025-54121: Starlette has possible denial-of-service vector when parsing
  large files in multipart forms'
---

# CVE-2025-54121: Starlette has possible denial-of-service vector when parsing large files in multipart forms

## TL;DR
Starlette has possible denial-of-service vector when parsing large files in multipart forms

## Key Points
- cve / CVE-2025-54121 / GHSA-2c2j-9gv5-cj73 / severity:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L / starlette / PyPI

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
**Advisory:** GHSA-2c2j-9gv5-cj73 (CVE-2025-54121)

**Affected (your watchlist):**
- `PyPI:starlette` 0.41.3 → fixed in 0.47.2 [docker/docker-portal]

**Details:**
### Summary
When parsing a multi-part form with large files (greater than the [default max spool size](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/formparsers.py#L126)) `starlette` will block the main thread to roll the file over to disk. This blocks the event thread which means we can't accept new connections.

### Details
Please see this discussion for details: https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403. In summary the following UploadFile code (copied from [here](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14)) has a minor bug. Instead of just checking for `self._in_memory` we should also check if the additional bytes will cause a rollover.

```python

    @property
    def _in_memory(self) -> bool:
        # check for SpooledTemporaryFile._rolled
        rolled_to_disk = getattr(self.file, "_rolled", True)
        return not rolled_to_disk

    async def write(self, data: bytes) -> None:
        if self.size is not None:
            self.size += len(data)

        if self._in_memory:
            self.file.write(data)
        else:
            await run_in_threadpool(self.file.write, data)
```

I have already created a PR which fixes the problem: https://github.com/encode/starlette/pull/2962


### PoC
See the discussion [here](https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403) for steps on how to reproduce.

### Impact
To be honest, very low and not many users will be impacted. Parsing large forms is already CPU intensive so the additional IO block doesn't slow down `starlette` that much on systems with modern HDDs/SSDs. If someone is running on tape they might see a greater impact.

**References:**
- https://github.com/encode/starlette/security/advisories/GHSA-2c2j-9gv5-cj73
- https://nvd.nist.gov/vuln/detail/CVE-2025-54121
- https://github.com/encode/starlette/commit/9f7ec2eb512fcc3fe90b43cb9dd9e1d08696bec1
- https://github.com/encode/starlette
- https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14
- https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403

_Data: OSV.dev (upstream: ghsa) — https://osv.dev/vulnerability/GHSA-2c2j-9gv5-cj73_

## Source
元記事: [CVE-2025-54121: Starlette has possible denial-of-service vector when parsing large files in multipart forms](https://osv.dev/vulnerability/GHSA-2c2j-9gv5-cj73) — published 2025-07-21T19:34:23Z
