Headline
GHSA-3qj8-93xh-pwh2: Starlette allows an unauthenticated and remote attacker to specify any number of form fields or files
There MultipartParser usage in Encode’s Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.
Starlette allows an unauthenticated and remote attacker to specify any number of form fields or files
High severity GitHub Reviewed Published Apr 21, 2023 to the GitHub Advisory Database • Updated Apr 21, 2023
Related news
There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.