Known Vulnerabilities for Starlette by Kludex
Listed below are 8 of the newest known vulnerabilities associated with "Starlette" by "Kludex".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56076 json | PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attack... | Not Provided | 2026-06-18 | 2026-06-18 |
| CVE-2026-48818 json | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSR... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-48817 json | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint sele... | Not Provided | 2026-06-17 | 2026-06-18 |
| CVE-2026-48710 json | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated b... | Not Provided | 2026-05-26 | 2026-06-16 |
| CVE-2026-45554 json | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-44716 json | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-40115 json | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the WSGI-based recipe registry server (server.py) reads the entire... | Not Provided | 2026-04-09 | 2026-04-13 |
| CVE-2026-32847 json | DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py ... | Not Provided | 2026-05-28 | 2026-05-30 |