-------------------------------------------------------------------------
Debian LTS Advisory DLA-4711-1                [email protected]
https://www.debian.org/lts/security/                       Daniel Leidert
August 01, 2026                               https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : starlette
Version        : 0.26.1-1+deb12u2
CVE ID         : CVE-2026-48817 CVE-2026-54282 CVE-2026-54283
Debian Bug     : 1140631 1140632

Multiple vulnerabilities were found in starlette, a lightweight ASGI
(Asynchronous Server Gateway Interface) framework/toolkit.

CVE-2026-48817

   A vulnerability exists where an HTTPEndpoint subclass is registered
   through Route() without an explicit methods argument, and the route
   does not constrain the method and every method reaches the endpoint.

CVE-2026-54282

   A vulnerability exists where the HTTP request path is not validated
   before being used to reconstruct request.url which can poison
   request.url.hostname and request.url.netloc.

CVE-2026-54283

   The max_fields and max_part_size limits for request.form() are enforced
   for multipart/form-data, but silently ignored for application/x-www-
   form-urlencoded.

For Debian 12 bookworm, these problems have been fixed in version
0.26.1-1+deb12u2.

We recommend that you upgrade your starlette packages.

For the detailed security status of starlette please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/starlette

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to