© 2025-2026 PySpect
First version without a known vulnerability: 2.22.0
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header
Fixed in: 2.22.0
Litestar has HTML Injection Through its CSRF Token
Fixed in: 2.22.0
Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)
Fixed in: 2.20.0
Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patterns
Fixed in: 2.20.0
Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed origins
Fixed in: 2.20.0
Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
Fixed in: 2.18.0
Litestar has potential log injection in exception logging
Fixed in: 2.17.0
Litestar allows unbounded resource consumption (DoS vulnerability)
Fixed in: 2.13.0, 53c1473b5ff7502816a9a339ffc90731bb0c2138
Litestar and Starlite vulnerable to Path Traversal
Fixed in: 2.8.3, 1.51.16, 2.7.2, 2.6.4