36 lines
1.5 KiB
JSON
36 lines
1.5 KiB
JSON
{
|
|
"review_by": "2026-08-31",
|
|
"package": "starlette",
|
|
"constraint": "FastAPI 0.139.2 requires Starlette below 0.53; patched Starlette releases start at 1.0.1 or later.",
|
|
"compensating_controls": [
|
|
"GeoIntel rejects missing or ambiguous Host headers and request targets before request.url is accessed.",
|
|
"Application code logs the raw ASGI path and does not use request.url for authorization or routing.",
|
|
"application/x-www-form-urlencoded is rejected; supported uploads use bounded multipart requests behind nginx.",
|
|
"The release image is Linux, no HTTPEndpoint route class is used, and the Windows StaticFiles advisory is not applicable."
|
|
],
|
|
"advisories": [
|
|
{
|
|
"id": "PYSEC-2026-161",
|
|
"reason": "Host/path ambiguity is rejected at the outer request middleware and request.url is not a security boundary."
|
|
},
|
|
{
|
|
"id": "PYSEC-2026-248",
|
|
"reason": "Non-slash request paths and ambiguous Host values are rejected before URL reconstruction."
|
|
},
|
|
{
|
|
"id": "PYSEC-2026-249",
|
|
"aliases": ["CVE-2026-54283"],
|
|
"reason": "GeoIntel rejects application/x-www-form-urlencoded before Starlette form parsing."
|
|
},
|
|
{
|
|
"id": "PYSEC-2026-2280",
|
|
"reason": "GeoIntel registers FastAPI APIRouter functions and has no Starlette HTTPEndpoint routes."
|
|
},
|
|
{
|
|
"id": "PYSEC-2026-2281",
|
|
"aliases": ["CVE-2026-48818"],
|
|
"reason": "The supported all-in-one production runtime is Linux; the advisory affects Windows StaticFiles."
|
|
}
|
|
]
|
|
}
|