#1140631 starlette: CVE-2026-54283

Package:
src:starlette
Source:
src:starlette
Submitter:
Salvatore Bonaccorso
Date:
2026-07-29 13:07:02 UTC
Severity:
normal
Tags:
#1140631#5
Date:
2026-06-23 19:19:36 UTC
From:
To:
Hi,

The following vulnerability was published for starlette.

CVE-2026-54283[0]:
| Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until
| 1.3.1, request.form() accepts max_fields and max_part_size to bound
| resource consumption while parsing form data. These limits are
| enforced for multipart/form-data, but silently ignored for
| application/x-www-form-urlencoded. An unauthenticated attacker can
| therefore send a urlencoded body with an arbitrarily large number of
| fields or an arbitrarily large field, even when the application
| configured limits it believed would apply. This vulnerability is
| fixed in 1.3.1.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54283
https://www.cve.org/CVERecord?id=CVE-2026-54283
[1] https://github.com/Kludex/starlette/pull/3329
[2] https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq
[3] https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735

Regards,
Salvatore

#1140631#14
Date:
2026-07-29 13:05:39 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
starlette, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140631@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Matheus Polkorny <mpolkorny@gmail.com> (supplier of updated starlette package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 09 Jul 2026 21:45:58 -0300
Source: starlette
Architecture: source
Version: 1.3.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Matheus Polkorny <mpolkorny@gmail.com>
Closes: 1140631 1140632
Changes:
 starlette (1.3.1-1) unstable; urgency=medium
 .
   * New upstream version 1.3.1
     Fixed CVE issues in upstream version 1.3.0: (Closes: #1140632)
     CVE-2026-54282: Unvalidated request path concatenated into authority
                     poisons request.url.hostname
     Fixed CVE issues in upstream version 1.3.1: (Closes: #1140631)
     CVE-2026-54283: request.form() limits silently ignored for
                     application/x-www-form-urlencoded enable DoS
   * d/control:
     - Bump Standards-Version to 4.7.4 (no changes)
     - Update Build-Depends and Recommends to reflect upstream
Checksums-Sha1:
 4e4e2446ff250f25c94f2ce640d7a952d50e638e 2439 starlette_1.3.1-1.dsc
 9e1ea1cbc5d7d882897c18269853b2aaa9b0c9b0 2702556 starlette_1.3.1.orig.tar.gz
 e8e7485fc6ceefff8b3934225442f2070202fc23 5448 starlette_1.3.1-1.debian.tar.xz
 89546787aa619b30bcf72b862f70aa6f811c2dda 7407 starlette_1.3.1-1_amd64.buildinfo
Checksums-Sha256:
 c0ed30097a61e48737a562a63e7d9fe0d38ba37488a9c8eec1f5cc4cdae90f92 2439 starlette_1.3.1-1.dsc
 fa9a03542c5851c7a81b83166ad82b829e6ce1ec643d4a3019d807355e4ed138 2702556 starlette_1.3.1.orig.tar.gz
 32e9b695c8e2e7ef179eef4d9805c34a9009a8f89e0396a1da1e6ee1200427ce 5448 starlette_1.3.1-1.debian.tar.xz
 7002849065074d3ec36ddc458d64f9b4d28a943435dd21cf6122799356cafdbb 7407 starlette_1.3.1-1_amd64.buildinfo
Files:
 b3d41b9f9081e679a8b953405c109ed0 2439 python optional starlette_1.3.1-1.dsc
 74b029602daf5a3fa6cbc38b002498e0 2702556 python optional starlette_1.3.1.orig.tar.gz
 f49a5f8bb6885b665cba18bc881d1338 5448 python optional starlette_1.3.1-1.debian.tar.xz
 bd0e42b749d04f5e3e220d12a48c1703 7407 python optional starlette_1.3.1-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtw38bxNP7PwBHmKqgwFgFCUdHbAFAmpp9FQACgkQgwFgFCUd
HbCglhAAqPbchELFvEmkWtmhcA5eE1KUbrJJh4IvOr+9IyM+s/HBI/Ka9+lYhlDA
fwSvK4S9/mcrkFP+EAEwFyAcDcvk0Z5s3W3ny8V0AlMfVOnFZZgIuf06zavFCYjr
i6j6LiYU/CWWS7S8K5f7hwdkBiJLEGbxdtTe9PVJOcJsOpnJIcZBjiLpTPY+ZOFX
Eru/J3bRWvuq2GxiDN9e3HOV/4cDcVIz1ACqfLv+lD64vSgpOy+7Utk/Mez4NO4C
Xe2iIF/i6LzcmM9jarn47T9r51f3CuFxlTGs4Fd8P52uhUEj5c5iaDsBvb7AfpjJ
s7UEfwWNavjosgMcGxlwPeVj6AWhiBJTF7yrnjlG5i1tH9VaEDOwAlhWas4m28hG
OT/hV8w5i2qmHjA2RoxENvdveWZRuRGexUkYHQHUqlGur1PrHNI8zV+ehOvy2lFx
oazgRtCFA+mvQdlUUU1KVCcWZgFOwPs/mpqWEoZoug+pFUP/x6EK62TpwLZV+qX6
AK1zkOBYUXq/NFe9WUcfdGBV3ap7Damf40wxMg0SYSg8vyOjMo3GozcIrAaXHnk/
ihMUAI5gbpQCu3EnoeCwlUHbx4aBSKpKIMWhEBEGwxEQQq7Za5axA2mZmaXekipq
Oij0V5R4M+VuNKEykcDc8IGxgWEE1/vCfcTUXur2OpuenZGtU04=
=GZia
-----END PGP SIGNATURE-----