------------------------------------------------------------------------- Debian LTS Advisory DLA-4711-1 [email protected] https://www.debian.org/lts/security/ Daniel Leidert August 01, 2026 https://wiki.debian.org/LTS -------------------------------------------------------------------------
Package : starlette Version : 0.26.1-1+deb12u2 CVE ID : CVE-2026-48817 CVE-2026-54282 CVE-2026-54283 Debian Bug : 1140631 1140632 Multiple vulnerabilities were found in starlette, a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit. CVE-2026-48817 A vulnerability exists where an HTTPEndpoint subclass is registered through Route() without an explicit methods argument, and the route does not constrain the method and every method reaches the endpoint. CVE-2026-54282 A vulnerability exists where the HTTP request path is not validated before being used to reconstruct request.url which can poison request.url.hostname and request.url.netloc. CVE-2026-54283 The max_fields and max_part_size limits for request.form() are enforced for multipart/form-data, but silently ignored for application/x-www- form-urlencoded. For Debian 12 bookworm, these problems have been fixed in version 0.26.1-1+deb12u2. We recommend that you upgrade your starlette packages. For the detailed security status of starlette please refer to its security tracker page at: https://security-tracker.debian.org/tracker/starlette Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
signature.asc
Description: This is a digitally signed message part
