---
title: 'Topic: starlette'
canonical_url: https://portal.chinng-lab-srv.dev/topics/starlette.md
content_kind: topic
updated_at: '2026-07-16T06:46:07Z'
---

# Topic: starlette

> Stable topic monitoring page generated from normalized published metadata.

- Canonical: https://portal.chinng-lab-srv.dev/topics/starlette.md
- Last updated: 2026-07-16T06:46:07Z
- Search: https://portal.chinng-lab-srv.dev/api/search?q=starlette
- MCP: portal_search(q="starlette")

## Related categories

- security/library

## Related entities

- two-dose treatment
- VIATRIX
- HashTag
- Starlette
- Requested command
- OCTOPATH TRAVELER
- AND CaaaLL
- https://deploymentsafety.openai.com/gpt-5-6/gpt-5-6.pdf
- Method
- Missing People
- Ghost
- Link Header
- Validation Started

## Latest articles

- [CVE-2025-62727: Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``](https://portal.chinng-lab-srv.dev/security/library/security-20260711-dc1ff3.md): Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
- [CVE-2025-54121: Starlette has possible denial-of-service vector when parsing large files in multipart forms](https://portal.chinng-lab-srv.dev/security/library/security-20260711-aa726f.md): Starlette has possible denial-of-service vector when parsing large files in multipart forms
- [CVE-2026-54283 — starlette](https://portal.chinng-lab-srv.dev/security/library/security-20260711-d980d5.md): Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are…
- [CVE-2026-54282 — starlette](https://portal.chinng-lab-srv.dev/security/library/security-20260711-d36fb6.md): Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating…
- [CVE-2026-48817 — starlette](https://portal.chinng-lab-srv.dev/security/library/security-20260714-52fc4b.md): Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an att…
- [CVE-2026-48818 — starlette](https://portal.chinng-lab-srv.dev/security/library/security-20260714-163dc6.md): Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause os.path.realpath to…
- [CVE-2026-54283: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS](https://portal.chinng-lab-srv.dev/security/library/security-20260711-e1d2eb.md): Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
- [CVE-2026-54282: Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname](https://portal.chinng-lab-srv.dev/security/library/security-20260711-b55652.md): Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
- [CVE-2026-48818: Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows](https://portal.chinng-lab-srv.dev/security/library/security-20260711-8dd28c.md): Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
- [CVE-2026-48817: Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`](https://portal.chinng-lab-srv.dev/security/library/security-20260711-fa0f6a.md): Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
- [CVE-2026-48710: Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks](https://portal.chinng-lab-srv.dev/security/library/security-20260711-4f7f03.md): Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
- [CVE-2026-48710: BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks](https://portal.chinng-lab-srv.dev/security/library/security-20260711-0ca3e6.md): BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks
- [CVE-2025-62727: Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``](https://portal.chinng-lab-srv.dev/security/library/security-20260711-a27c94.md): Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
- [CVE-2025-54121: Starlette has possible denial-of-service vector when parsing large files in multipart forms](https://portal.chinng-lab-srv.dev/security/library/security-20260711-cd40e8.md): Starlette has possible denial-of-service vector when parsing large files in multipart forms
