CVE-2026-54283Disclosure(encode / starlette)
LOWCVSS 7.5 · HIGHExploit discussion active in current signal (1 latest mentions)
Immediate actions
- Patch encode starlette systems immediately
- Hunt for exploitation attempts and persistence artifacts
- Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply. This vulnerability is fixed in 1.3.1.
Sources & remediation
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
Are you affected?
If you run products in this scope, you should treat this CVE as relevant to your environment.
- starlette
Threat summary
- Public PoC is present in monitored signal
- Patch or workaround signal is available
- 4 mentions across 4 observed days
- Momentum state: stable
What's happening
- PoC mentioned or linked in 1 signal
- Patch or workaround mentioned in 1 signal
- Technical details provided in 2 signals
- Disclosure: 2 classified signals
- General: 1 classified signal
- Peaked 3d ago at 1 mentions (2026-06-15); latest day: 1
- 4 total mentions across 4 days
Affected systems
Deep dive
Activity timeline4 mentions / 4d
Signal classification3 categories
Referenced assets3 URLs
Classification over time
| Date | Total | Labels |
|---|
| 2026-06-15 | 1 | Disclosure1 |
| 2026-06-16 | 1 | General1 |
| 2026-06-24 | 1 | Patch1 |
| 2026-08-26 | 1 | Disclosure1 |
CPE platform detail1 entries
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | encode | starlette | - | python | - |
