CVE-2026-54283

Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply. This vulnerability is fixed in 1.3.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:*

History

26 Jun 2026, 19:16

Type Values Removed Values Added
References () https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq - () https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq - Mitigation, Vendor Advisory
CPE cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:*
First Time Encode starlette
Encode

22 Jun 2026, 18:28

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 18:16

Updated : 2026-06-26 19:16


NVD link : CVE-2026-54283

Mitre link : CVE-2026-54283

CVE.ORG link : CVE-2026-54283


JSON object : View

Products Affected

encode

  • starlette
CWE
CWE-770

Allocation of Resources Without Limits or Throttling