© 2025-2026 PySpect
First version without a known vulnerability: 1.3.1
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
Fixed in: 1.3.1
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
Fixed in: 1.3.0
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
Fixed in: 1.1.0
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
Fixed in: 1.1.0
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Fixed in: 1.0.1
Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``
Fixed in: 0.49.1
Starlette has possible denial-of-service vector when parsing large files in multipart forms
Fixed in: 0.47.2
Starlette Denial of service (DoS) via multipart/form-data
Fixed in: 0.40.0
Starlette has Path Traversal vulnerability in StaticFiles
Fixed in: 0.27.0
MultipartParser denial of service with too many fields or files
Fixed in: 0.25.0, 8c74c2c8dba7030154f8af18e016136bea1938fa