litestar vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-48061Mediumlitestar: Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host headerCVE-2026-48060Highlitestar: Litestar has HTML Injection Through its CSRF TokenCVE-2026-25480Mediumlitestar: Litestar's FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)CVE-2026-25479Mediumlitestar: Litestar's AllowedHosts has a validation bypass due to unescaped regex metacharacters in configured host patternsCVE-2026-25478Highlitestar: Litestar's CORS origin allowlist has a bypass due to unescaped regex metacharacters in allowed originsCVE-2025-59152Highlitestar: Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit EvasionGHSA-674P-XV2X-RF3GLowlitestar: Litestar has potential log injection in exception loggingCVE-2024-52581Highlitestar: Litestar allows unbounded resource consumption (DoS vulnerability) CVE-2024-32982Highlitestar: Litestar and Starlite vulnerable to Path Traversal

Stop the waste.
Protect your environment with Kodem.