<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T22:22:52.840684+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-10819</id>
    <title>bdu:2025-10819</title>
    <updated>2026-10-03T22:22:53.226266+00:00</updated>
    <content>bdu:2025-10819</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-10819"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-cycode-cve-2025-54121</id>
    <title>BREW-cycode-CVE-2025-54121 — Starlette has possible denial-of-service vector when parsing large files in multipart forms</title>
    <updated>2026-10-03T22:22:53.226351+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: cycode</p>
<p>### Summary
When parsing a multi-part form with large files (greater than the [default max spool size](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/formparsers.py#L126)) `starlette` will block the main thread to roll the file over to disk. This blocks the event thread which means we can't accept new connections.</p>
<p>### Details
Please see this discussion for details: https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403. In summary the following UploadFile code (copied from [here](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14)) has a minor bug. Instead of just checking for `self._in_memory` we should also check if the additional bytes will cause a rollover.</p>
<p>```python</p>
<p>@property
    def _in_memory(self) -&gt; bool:
        # check for SpooledTemporaryFile._rolled
        rolled_to_disk = getattr(self.file, "_rolled", True)
        return not rolled_to_disk</p>
<p>async def write(self, data: bytes) -&gt; None:
        if self.size is not None:
            self.size += len(data)</p>
<p>if self._in_memory:
            self.file.write(data)
        else:
            await run_in_threadpool(self.file.write, data)
```</p>
<p>I have already created a PR which fixes the problem: https://github.com/encode/starlette/pull/2962</p>
<p>### PoC
See the discussion [here](https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403) for s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-cycode-cve-2025-54121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1051</id>
    <title>certfr-2025-avi-1051 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T22:22:53.226421+00:00</updated>
    <content>certfr-2025-avi-1051</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1051"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-al63130</id>
    <title>Withdrawn: CLEANSTART-2026-AL63130 — Security fixes in litellm-database 1.96.0-r0</title>
    <updated>2026-10-03T22:22:53.226452+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: litellm-database</p>
<p>Package litellm-database version 1.96.0-r0 fixes 5 vulnerabilities: CVE-2026-54282, CVE-2025-62727, CVE-2026-48818, CVE-2026-54283, CVE-2025-54121</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-al63130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248246</id>
    <title>EUVD-2026-248246</title>
    <updated>2026-10-03T22:22:53.226495+00:00</updated>
    <content>EUVD-2026-248246</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248246"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54121</id>
    <title>fkie_cve-2025-54121</title>
    <updated>2026-10-03T22:22:53.226516+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will block the main thread to roll the file over to disk. This blocks the event thread which means the application can't accept new connections. The UploadFile code has a minor bug where instead of just checking for self._in_memory, the logic should also check if the additional bytes will cause a rollover. The vulnerability is fixed in version 0.47.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-54121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2c2j-9gv5-cj73</id>
    <title>GHSA-2c2j-9gv5-cj73 — Starlette has possible denial-of-service vector when parsing large files in multipart forms</title>
    <updated>2026-10-03T22:22:53.226559+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: starlette</p>
<p>### Summary
When parsing a multi-part form with large files (greater than the [default max spool size](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/formparsers.py#L126)) `starlette` will block the main thread to roll the file over to disk. This blocks the event thread which means we can't accept new connections.</p>
<p>### Details
Please see this discussion for details: https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403. In summary the following UploadFile code (copied from [here](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14)) has a minor bug. Instead of just checking for `self._in_memory` we should also check if the additional bytes will cause a rollover.</p>
<p>```python</p>
<p>@property
    def _in_memory(self) -&gt; bool:
        # check for SpooledTemporaryFile._rolled
        rolled_to_disk = getattr(self.file, "_rolled", True)
        return not rolled_to_disk</p>
<p>async def write(self, data: bytes) -&gt; None:
        if self.size is not None:
            self.size += len(data)</p>
<p>if self._in_memory:
            self.file.write(data)
        else:
            await run_in_threadpool(self.file.write, data)
```</p>
<p>I have already created a PR which fixes the problem: https://github.com/encode/starlette/pull/2962</p>
<p>### PoC
See the discussion [here](https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403) for s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2c2j-9gv5-cj73"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15381-1</id>
    <title>openSUSE-SU-2025:15381-1 — python311-starlette-0.47.2-1.1 on GA media</title>
    <updated>2026-10-03T22:22:53.226646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-starlette-0.47.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15381-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1941</id>
    <title>PYSEC-2026-1941 — Starlette has possible denial-of-service vector when parsing large files in multipart forms</title>
    <updated>2026-10-03T22:22:53.226683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: starlette</p>
<p>### Summary
When parsing a multi-part form with large files (greater than the [default max spool size](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/formparsers.py#L126)) `starlette` will block the main thread to roll the file over to disk. This blocks the event thread which means we can't accept new connections.</p>
<p>### Details
Please see this discussion for details: https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403. In summary the following UploadFile code (copied from [here](https://github.com/encode/starlette/blob/fa5355442753f794965ae1af0f87f9fec1b9a3de/starlette/datastructures.py#L436C5-L447C14)) has a minor bug. Instead of just checking for `self._in_memory` we should also check if the additional bytes will cause a rollover.</p>
<p>```python</p>
<p>@property
    def _in_memory(self) -&gt; bool:
        # check for SpooledTemporaryFile._rolled
        rolled_to_disk = getattr(self.file, "_rolled", True)
        return not rolled_to_disk</p>
<p>async def write(self, data: bytes) -&gt; None:
        if self.size is not None:
            self.size += len(data)</p>
<p>if self._in_memory:
            self.file.write(data)
        else:
            await run_in_threadpool(self.file.write, data)
```</p>
<p>I have already created a PR which fixes the problem: https://github.com/encode/starlette/pull/2962</p>
<p>### PoC
See the discussion [here](https://github.com/encode/starlette/discussions/2927#discussioncomment-13721403) for s…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1941"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02544-1</id>
    <title>SUSE-SU-2025:02544-1 — Security update for python-starlette</title>
    <updated>2026-10-03T22:22:53.226770+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-starlette</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02544-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54121</id>
    <title>UBUNTU-CVE-2025-54121</title>
    <updated>2026-10-03T22:22:53.226796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: starlette, Ubuntu:24.04:LTS: starlette, Ubuntu:25.10: starlette, Ubuntu:26.04:LTS: starlette</p>
<p>Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part form with large files (greater than the default max spool size) starlette will block the main thread to roll the file over to disk. This blocks the event thread which means the application can't accept new connections. The UploadFile code has a minor bug where instead of just checking for self._in_memory, the logic should also check if the additional bytes will cause a rollover. The vulnerability is fixed in version 0.47.2.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54121"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2534</id>
    <title>WID-SEC-W-2025-2534 — IBM Business Automation Workflow: Mehrere Schwachstellen</title>
    <updated>2026-10-03T22:22:53.226852+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in IBM Business Automation Workflow ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2534"/>
  </entry>
</feed>
