Skip to main content

Vendor archive

encode CVEs

Beta · best-effort

12 CVEs tagged to vendor encode1 Critical, 5 High, 4 Medium, 2 Low, 0 Unrated.

CVE-2026-54283

Published Jun 22, 2026

Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form dat…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-54282

Published Jun 22, 2026

Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebu…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48817

Published Jun 17, 2026

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and loo…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-48818

Published Jun 17, 2026

Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause…

CVSS 7.5 · High
evidence mentions
10
Buzz score
37.0
Vendor/product tagsBeta · best-effort

CVE-2026-48710

Published May 26, 2026

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because…

CVSS 6.5 · Medium
evidence mentions
28
Buzz score
50.0
Vendor/product tagsBeta · best-effort

CVE-2023-29159

Published Jun 1, 2023

Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was buil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30798

Published Apr 21, 2023

There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or fil…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2021-41945

Published Apr 28, 2022

Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-7695

Published Jul 27, 2020

Uvicorn before 0.11.7 is vulnerable to HTTP response splitting. CRLF sequences are not escaped in the value of HTTP headers. Attackers can exploit this to add arbitrary headers to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7694

Published Jul 27, 2020

This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, th…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1