- Package:
- src:starlette
- Source:
- src:starlette
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-31 13:49:06 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for starlette. CVE-2026-54283[0]: | Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until | 1.3.1, request.form() accepts max_fields and max_part_size to bound | resource consumption while parsing form data. These limits are | enforced for multipart/form-data, but silently ignored for | application/x-www-form-urlencoded. An unauthenticated attacker can | therefore send a urlencoded body with an arbitrarily large number of | fields or an arbitrarily large field, even when the application | configured limits it believed would apply. This vulnerability is | fixed in 1.3.1. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-54283 https://www.cve.org/CVERecord?id=CVE-2026-54283 [1] https://github.com/Kludex/starlette/pull/3329 [2] https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq [3] https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
starlette, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1140631@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matheus Polkorny <mpolkorny@gmail.com> (supplier of updated starlette package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 09 Jul 2026 21:45:58 -0300
Source: starlette
Architecture: source
Version: 1.3.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Matheus Polkorny <mpolkorny@gmail.com>
Closes: 1140631 1140632
Changes:
starlette (1.3.1-1) unstable; urgency=medium
.
* New upstream version 1.3.1
Fixed CVE issues in upstream version 1.3.0: (Closes: #1140632)
CVE-2026-54282: Unvalidated request path concatenated into authority
poisons request.url.hostname
Fixed CVE issues in upstream version 1.3.1: (Closes: #1140631)
CVE-2026-54283: request.form() limits silently ignored for
application/x-www-form-urlencoded enable DoS
* d/control:
- Bump Standards-Version to 4.7.4 (no changes)
- Update Build-Depends and Recommends to reflect upstream
Checksums-Sha1:
4e4e2446ff250f25c94f2ce640d7a952d50e638e 2439 starlette_1.3.1-1.dsc
9e1ea1cbc5d7d882897c18269853b2aaa9b0c9b0 2702556 starlette_1.3.1.orig.tar.gz
e8e7485fc6ceefff8b3934225442f2070202fc23 5448 starlette_1.3.1-1.debian.tar.xz
89546787aa619b30bcf72b862f70aa6f811c2dda 7407 starlette_1.3.1-1_amd64.buildinfo
Checksums-Sha256:
c0ed30097a61e48737a562a63e7d9fe0d38ba37488a9c8eec1f5cc4cdae90f92 2439 starlette_1.3.1-1.dsc
fa9a03542c5851c7a81b83166ad82b829e6ce1ec643d4a3019d807355e4ed138 2702556 starlette_1.3.1.orig.tar.gz
32e9b695c8e2e7ef179eef4d9805c34a9009a8f89e0396a1da1e6ee1200427ce 5448 starlette_1.3.1-1.debian.tar.xz
7002849065074d3ec36ddc458d64f9b4d28a943435dd21cf6122799356cafdbb 7407 starlette_1.3.1-1_amd64.buildinfo
Files:
b3d41b9f9081e679a8b953405c109ed0 2439 python optional starlette_1.3.1-1.dsc
74b029602daf5a3fa6cbc38b002498e0 2702556 python optional starlette_1.3.1.orig.tar.gz
f49a5f8bb6885b665cba18bc881d1338 5448 python optional starlette_1.3.1-1.debian.tar.xz
bd0e42b749d04f5e3e220d12a48c1703 7407 python optional starlette_1.3.1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmpp9FQACgkQgwFgFCUd
HbCglhAAqPbchELFvEmkWtmhcA5eE1KUbrJJh4IvOr+9IyM+s/HBI/Ka9+lYhlDA
fwSvK4S9/mcrkFP+EAEwFyAcDcvk0Z5s3W3ny8V0AlMfVOnFZZgIuf06zavFCYjr
i6j6LiYU/CWWS7S8K5f7hwdkBiJLEGbxdtTe9PVJOcJsOpnJIcZBjiLpTPY+ZOFX
Eru/J3bRWvuq2GxiDN9e3HOV/4cDcVIz1ACqfLv+lD64vSgpOy+7Utk/Mez4NO4C
Xe2iIF/i6LzcmM9jarn47T9r51f3CuFxlTGs4Fd8P52uhUEj5c5iaDsBvb7AfpjJ
s7UEfwWNavjosgMcGxlwPeVj6AWhiBJTF7yrnjlG5i1tH9VaEDOwAlhWas4m28hG
OT/hV8w5i2qmHjA2RoxENvdveWZRuRGexUkYHQHUqlGur1PrHNI8zV+ehOvy2lFx
oazgRtCFA+mvQdlUUU1KVCcWZgFOwPs/mpqWEoZoug+pFUP/x6EK62TpwLZV+qX6
AK1zkOBYUXq/NFe9WUcfdGBV3ap7Damf40wxMg0SYSg8vyOjMo3GozcIrAaXHnk/
ihMUAI5gbpQCu3EnoeCwlUHbx4aBSKpKIMWhEBEGwxEQQq7Za5axA2mZmaXekipq
Oij0V5R4M+VuNKEykcDc8IGxgWEE1/vCfcTUXur2OpuenZGtU04=
=GZia
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
starlette, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1140631@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matheus Polkorny <mpolkorny@gmail.com> (supplier of updated starlette package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 25 Jul 2026 00:12:35 -0300
Source: starlette
Architecture: source
Version: 0.46.1-3+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Piotr Ożarowski <piotr@debian.org>
Changed-By: Matheus Polkorny <mpolkorny@gmail.com>
Closes: 1140631 1140632
Changes:
starlette (0.46.1-3+deb13u3) trixie-security; urgency=medium
.
* Team upload.
* d/patches: (Closes: #1140631, #1140632)
- CVE-2026-48817: Import and backport upstream patch
(Prevent unintended HTTPEndpoint method dispatch)
- CVE-2026-54282: Import upstream patch
(Validate request paths to prevent host confusion)
- CVE-2026-54283: Import and backport upstream patch
(Enforce max_fields and max_part_size limits)
Checksums-Sha1:
b7e6c0043c772b167aa8bf064671ab824a466ef8 2495 starlette_0.46.1-3+deb13u3.dsc
9b40ecf58e5118bae9fc5b2c0f8f9cef1ade3971 2580102 starlette_0.46.1.orig.tar.gz
59475e3e0bb41bacef51ff30fde64740a6c40f49 11612 starlette_0.46.1-3+deb13u3.debian.tar.xz
7e277eee846fe6c73c4211c5120b75983597f08b 7044 starlette_0.46.1-3+deb13u3_source.buildinfo
Checksums-Sha256:
f3016fa3bcbe6c77c89cadb56cb17970c64c0bf26e61c69f8800663ac6ada676 2495 starlette_0.46.1-3+deb13u3.dsc
3c88d58ee4bd1bb807c0d1acb381838afc7752f9ddaec81bbe4383611d833230 2580102 starlette_0.46.1.orig.tar.gz
72e28a6d618dab03df8131a7f4cc3ff85acb93a943fdd0d2c8f2466210ad61ce 11612 starlette_0.46.1-3+deb13u3.debian.tar.xz
c449e6b55e3327729420b0e245ec1ee3ab896147c8daa3fb4df8b41bfcc72de7 7044 starlette_0.46.1-3+deb13u3_source.buildinfo
Files:
448d612b7ce1ba18998dc4ac4adec5c6 2495 python optional starlette_0.46.1-3+deb13u3.dsc
01d82f7d2cc4509628ee4a97e8618c5e 2580102 python optional starlette_0.46.1.orig.tar.gz
890398fac1d34740965614e0dfa24cb0 11612 python optional starlette_0.46.1-3+deb13u3.debian.tar.xz
1398cfd3d1f25dc86e21b2903a7b0359 7044 python optional starlette_0.46.1-3+deb13u3_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmqPHncACgkQt4M9ggJ8
mQuyOg/+LuW44Md7pJstBdzLTNsmRHeeWYS3RObWRuQv3uILJgnw6NYhvoKFpQpX
qchQoLOkonRyyH3Viy+o0xzRpH91GG92FzPmHcO+9z06MpBhZzyxZF/b/plAQ3Gb
KsbB0qjTAJ9byzPe7CwEbsusuxbCo1ORiuakAJVhIkQbDyiPdXA4XoAiQie7i/wi
9XLYxtsbbqMQDwQ9SX/85e12sPFCD/zz3UdjsBY6eKD3s0YsiPYC/ls9VJAgVIx2
uxm2DQU/PpqTE1KtL9h2Uvtpq6g26GUaFHoiAu5oKE672JRA6VIhTiWpOnltwQHE
KIJfGYupvXybPJggJut5NHCUeIv9i9jTwQgJSlnNZFeQuMjn2QcIGXU/3itige+D
9EQMnI/S6S5vrlXnm2chBKXyDf+WyO1vR8C0dQm70XkOWNPDRw01oSvxkDP9PGYC
JjiUEFPP06QQaurXBRMeaFz2OMLtyyNMEU+ii0+T9JDjn5AF1zqwz0ItGNH7bYN+
a+HxkzX8oKGWL9VbCRTNN4bwJw8cgks889Nn2PDg2nVlZfTC4LnCTd57QMD9GStl
yrmuffFboQ9nfVh4qRcgOgS0wKTxXi3BIaSj93smNK1hiYdM/uIs9rEoJdA1rt/h
1wc6Vx3MMaJ2iwoXnyinhyrkYYM+mwzheLB2F7c13gsadAHNEYA=
=EZLs
-----END PGP SIGNATURE-----