CVE-2026-25480Disclosure(litestar / litestar)

LOWCVSS 6.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators, creating key collisions. When FileStore is used as response-cache backend, an unauthenticated remote attacker can trigger cache key collisions via crafted paths, causing one URL to serve cached responses of another (cache poisoning/mixup). This vulnerability is fixed in 2.20.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-176

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • litestar

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
litestar

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-09: 3Technical Details · 2026-02-09: 302-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25480 Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.20.0, FileStore maps cache keys to filenames using Unicode NFKD normalization and or… https://www.cve.org/CVERecord?id=CVE-2026-25480

    Post summary

    CVE‑2026‑25480 is disclosed for the Litestar ASGI framework (pre‑2.20.0), detailing a cache key mapping issue via Unicode NFKD normalization, with no PoC, exploit, patch, or active exploitation information provided.

    00010132
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25480 Cache Poisoning Vulnerability in Litestar FileStore Prior to 2.20.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25480

    Post summary

    The text announces CVE-2026-25480 as a cache poisoning flaw in Litestar FileStore versions before 2.20.0, without any evidence of exploitation or mitigation steps.

    0000034
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25480: The Kelvin Collision: Breaking Litestar's Cache with Basic Arithmetic A critical flaw in Litestar's FileStore component allows remote attackers to poison the server-side cache by exploiting a naive filename sanitization algorithm. By c... https://cvereports.com/reports/CVE-2026-25480

    Post summary

    A critical cache poisoning flaw in Litestar's FileStore component due to naive filename sanitization, enabling remote attackers to poison server‑side cache; no PoC, exploit, active exploitation, or patch is discussed.

    0000025
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applitestarlitestar---

Explore more