Your message dated Mon, 31 Aug 2026 13:48:58 +0000
with message-id <[email protected]>
and subject line Bug#1140631: fixed in starlette 0.46.1-3+deb13u3
has caused the Debian Bug report #1140631,
regarding starlette: CVE-2026-54283
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1140631: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140631
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: starlette
Version: 1.1.0-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/Kludex/starlette/pull/3329
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 0.26.1-1
Hi,
The following vulnerability was published for starlette.
CVE-2026-54283[0]:
| Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until
| 1.3.1, request.form() accepts max_fields and max_part_size to bound
| resource consumption while parsing form data. These limits are
| enforced for multipart/form-data, but silently ignored for
| application/x-www-form-urlencoded. An unauthenticated attacker can
| therefore send a urlencoded body with an arbitrarily large number of
| fields or an arbitrarily large field, even when the application
| configured limits it believed would apply. This vulnerability is
| fixed in 1.3.1.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-54283
https://www.cve.org/CVERecord?id=CVE-2026-54283
[1] https://github.com/Kludex/starlette/pull/3329
[2] https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq
[3]
https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: starlette
Source-Version: 0.46.1-3+deb13u3
Done: Matheus Polkorny <[email protected]>
We believe that the bug you reported is fixed in the latest version of
starlette, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matheus Polkorny <[email protected]> (supplier of updated starlette package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 25 Jul 2026 00:12:35 -0300
Source: starlette
Architecture: source
Version: 0.46.1-3+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Piotr Ożarowski <[email protected]>
Changed-By: Matheus Polkorny <[email protected]>
Closes: 1140631 1140632
Changes:
starlette (0.46.1-3+deb13u3) trixie-security; urgency=medium
.
* Team upload.
* d/patches: (Closes: #1140631, #1140632)
- CVE-2026-48817: Import and backport upstream patch
(Prevent unintended HTTPEndpoint method dispatch)
- CVE-2026-54282: Import upstream patch
(Validate request paths to prevent host confusion)
- CVE-2026-54283: Import and backport upstream patch
(Enforce max_fields and max_part_size limits)
Checksums-Sha1:
b7e6c0043c772b167aa8bf064671ab824a466ef8 2495 starlette_0.46.1-3+deb13u3.dsc
9b40ecf58e5118bae9fc5b2c0f8f9cef1ade3971 2580102 starlette_0.46.1.orig.tar.gz
59475e3e0bb41bacef51ff30fde64740a6c40f49 11612
starlette_0.46.1-3+deb13u3.debian.tar.xz
7e277eee846fe6c73c4211c5120b75983597f08b 7044
starlette_0.46.1-3+deb13u3_source.buildinfo
Checksums-Sha256:
f3016fa3bcbe6c77c89cadb56cb17970c64c0bf26e61c69f8800663ac6ada676 2495
starlette_0.46.1-3+deb13u3.dsc
3c88d58ee4bd1bb807c0d1acb381838afc7752f9ddaec81bbe4383611d833230 2580102
starlette_0.46.1.orig.tar.gz
72e28a6d618dab03df8131a7f4cc3ff85acb93a943fdd0d2c8f2466210ad61ce 11612
starlette_0.46.1-3+deb13u3.debian.tar.xz
c449e6b55e3327729420b0e245ec1ee3ab896147c8daa3fb4df8b41bfcc72de7 7044
starlette_0.46.1-3+deb13u3_source.buildinfo
Files:
448d612b7ce1ba18998dc4ac4adec5c6 2495 python optional
starlette_0.46.1-3+deb13u3.dsc
01d82f7d2cc4509628ee4a97e8618c5e 2580102 python optional
starlette_0.46.1.orig.tar.gz
890398fac1d34740965614e0dfa24cb0 11612 python optional
starlette_0.46.1-3+deb13u3.debian.tar.xz
1398cfd3d1f25dc86e21b2903a7b0359 7044 python optional
starlette_0.46.1-3+deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmqPHncACgkQt4M9ggJ8
mQuyOg/+LuW44Md7pJstBdzLTNsmRHeeWYS3RObWRuQv3uILJgnw6NYhvoKFpQpX
qchQoLOkonRyyH3Viy+o0xzRpH91GG92FzPmHcO+9z06MpBhZzyxZF/b/plAQ3Gb
KsbB0qjTAJ9byzPe7CwEbsusuxbCo1ORiuakAJVhIkQbDyiPdXA4XoAiQie7i/wi
9XLYxtsbbqMQDwQ9SX/85e12sPFCD/zz3UdjsBY6eKD3s0YsiPYC/ls9VJAgVIx2
uxm2DQU/PpqTE1KtL9h2Uvtpq6g26GUaFHoiAu5oKE672JRA6VIhTiWpOnltwQHE
KIJfGYupvXybPJggJut5NHCUeIv9i9jTwQgJSlnNZFeQuMjn2QcIGXU/3itige+D
9EQMnI/S6S5vrlXnm2chBKXyDf+WyO1vR8C0dQm70XkOWNPDRw01oSvxkDP9PGYC
JjiUEFPP06QQaurXBRMeaFz2OMLtyyNMEU+ii0+T9JDjn5AF1zqwz0ItGNH7bYN+
a+HxkzX8oKGWL9VbCRTNN4bwJw8cgks889Nn2PDg2nVlZfTC4LnCTd57QMD9GStl
yrmuffFboQ9nfVh4qRcgOgS0wKTxXi3BIaSj93smNK1hiYdM/uIs9rEoJdA1rt/h
1wc6Vx3MMaJ2iwoXnyinhyrkYYM+mwzheLB2F7c13gsadAHNEYA=
=EZLs
-----END PGP SIGNATURE-----
pgpVkKYBTDL5f.pgp
Description: PGP signature
--- End Message ---