CVE-2026-54283

EUVD-2026-38319
Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply. This vulnerability is fixed in 1.3.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 32.53%
Affected Products (NVD)
VendorProductVersion
encodestarlette
0.4.1 ≤
𝑥
< 1.3.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
starlette
bookworm
vulnerable
bookworm (security)
0.26.1-1+deb12u2
fixed
bullseye
vulnerable
forky
vulnerable
sid
1.3.1-1
fixed
trixie
vulnerable
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
starlette
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage