Security: litestar-org/litestar
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host headerGHSA-3qmc-cj7q-62hv published
May 20, 2026 by provinzkrautModerate -
HTML Injection Through CSRF TokenGHSA-542p-wvx7-72m4 published
May 20, 2026 by provinzkrautHigh -
FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord + Unicode NFKD)GHSA-vxqx-rh46-q2pg published
Feb 8, 2026 by provinzkrautModerate -
CORS origin allowlist bypass due to unescaped regex metacharacters in allowed originsGHSA-2p2x-hpg8-cqp2 published
Feb 8, 2026 by provinzkrautHigh -
AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patternsGHSA-93ph-p7v4-hwh4 published
Feb 8, 2026 by provinzkrautModerate -
X-Forwarded-For Header Spoofing Bypasses Litestar Rate LimitingGHSA-hm36-ffrh-c77c published
Oct 5, 2025 by provinzkrautModerate -
Potential log injection in exception loggingGHSA-674p-xv2x-rf3g published
Aug 11, 2025 by provinzkrautLow -
Unbounded resource consumption (DoS vulnerability)GHSA-gjcc-jvgw-wvwj published
Nov 20, 2024 by provinzkrautHigh -
Environment Variable injection in `docs-preview.yml` workflowGHSA-4hq2-rpgc-r8r7 published
Aug 9, 2024 by JacobCoffeeHigh -
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Litestar and StarliteGHSA-83pv-qr33-2vcf published
May 6, 2024 by peterschuttHigh