litestar
PyPI7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting litestarpage 1 of 1
- CVE-2024-32982HIGHCVSS 8.2EG 8.2✓ Fixed in 2.6.42024-05-06
vulnerable: 2.0.0 ... 2.6.3 (25 versions)
Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a Local File Inclusion (LFI) vulnerability has been discovered in the static file serving component of LiteStar. This vul…
- CVE-2024-42370HIGHCVSS 8.3EG 8.32024-08-12
vulnerable: 1.0.0a0 ... 2.9.1 (47 versions)
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions 2.10.0 and prior, Litestar's `docs-preview.yml` workflow is vulnerable to Environment Variable injection which may lead to secret exfiltration and repositor…
- CVE-2024-52581HIGHCVSS 7.5EG 7.5✓ Fixed in 2.13.02024-11-20
vulnerable: 1.0.0a0 ... 2.9.1 (50 versions)
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.13.0, the multipart form parser shipped with litestar expects the entire request body as a single byte string and there is no default limit for the t…
- CVE-2025-59152HIGHCVSS 7.5EG 7.5✓ Fixed in 2.18.02025-10-06
vulnerable: 2.17.0
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined…
- CVE-2026-25478HIGHCVSS 7.4EG 7.4✓ Fixed in 2.20.02026-02-09
vulnerable: 2.19.0
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, CORSConfig.allowed_origins_regex is constructed using a regex built from configured allowlist values and used with fullmatch() for validation. Because …
- CVE-2026-25479MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.20.02026-02-09
vulnerable: 2.19.0
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, in litestar.middleware.allowed_hosts, allowlist entries are compiled into regex patterns in a way that allows regex metacharacters to retain special me…
- CVE-2026-25480MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.20.02026-02-09
vulnerable: 2.19.0
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators, creating key collisions. When FileSt…
Check whether litestar is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for litestar CVEs against the assets you own.
Start Free Scan →