<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T17:38:56.554250+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-254206</id>
    <title>EUVD-2026-254206</title>
    <updated>2026-10-06T17:38:56.557515+00:00</updated>
    <content>EUVD-2026-254206</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-254206"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-59152</id>
    <title>fkie_cve-2025-59152</title>
    <updated>2026-10-06T17:38:56.557548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined attackers. Litestar's RateLimitMiddleware uses `cache_key_from_request()` to generate cache keys for rate limiting. When an X-Forwarded-For header is present, the middleware trusts it unconditionally and uses its value as part of the client identifier. Since clients can set arbitrary X-Forwarded-For values, each different spoofed IP creates a separate rate limit bucket. An attacker can rotate through different header values to avoid hitting any single bucket's limit. This affects any Litestar application using RateLimitMiddleware with default settings, which likely includes most applications that implement rate limiting. Version 2.18.0 contains a patch for the vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-59152"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hm36-ffrh-c77c</id>
    <title>GHSA-hm36-ffrh-c77c — Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion</title>
    <updated>2026-10-06T17:38:56.557591+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: litestar</p>
<p>While testing Litestar's RateLimitMiddleware, I discovered that rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined attackers.</p>
<p>## The Problem</p>
<p>Litestar's RateLimitMiddleware uses `cache_key_from_request()` to generate cache keys for rate limiting. When an X-Forwarded-For header is present, the middleware trusts it unconditionally and uses its value as part of the client identifier.</p>
<p>Since clients can set arbitrary X-Forwarded-For values, each different spoofed IP creates a separate rate limit bucket. An attacker can rotate through different header values to avoid hitting any single bucket's limit.</p>
<p>Looking at the relevant code in `litestar/middleware/rate_limit.py` around [line 127](https://github.com/litestar-org/litestar/blob/26f20ac6c52de2b4bf81161f7560c8bb4af6f382/litestar/middleware/rate_limit.py#L127), there's no validation of proxy headers or configuration for trusted proxies.</p>
<p>## Reproduction Steps</p>
<p>Here's a minimal test case</p>
<p>```python
from litestar import Litestar, get
from litestar.middleware.rate_limit import RateLimitConfig
import uvicorn</p>
<p>@get("/api/data")
def get_data() -&gt; dict:
    return {"message": "sensitive data"}</p>
<p>rate_config = RateLimitConfig(rate_limit=("minute", 2))</p>
<p>app = Litestar(
    route_handlers=[get_data],
    middleware=[rate_config.middleware]
)</p>
<p>if __name__ == "__main__":
    uvicorn.run(app, host="0.0.0.0", port=8000)
```</p>
<p>Testing the bypass…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hm36-ffrh-c77c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1553</id>
    <title>PYSEC-2026-1553 — Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion</title>
    <updated>2026-10-06T17:38:56.557647+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: litestar</p>
<p>While testing Litestar's RateLimitMiddleware, I discovered that rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined attackers.</p>
<p>## The Problem</p>
<p>Litestar's RateLimitMiddleware uses `cache_key_from_request()` to generate cache keys for rate limiting. When an X-Forwarded-For header is present, the middleware trusts it unconditionally and uses its value as part of the client identifier.</p>
<p>Since clients can set arbitrary X-Forwarded-For values, each different spoofed IP creates a separate rate limit bucket. An attacker can rotate through different header values to avoid hitting any single bucket's limit.</p>
<p>Looking at the relevant code in `litestar/middleware/rate_limit.py` around [line 127](https://github.com/litestar-org/litestar/blob/26f20ac6c52de2b4bf81161f7560c8bb4af6f382/litestar/middleware/rate_limit.py#L127), there's no validation of proxy headers or configuration for trusted proxies.</p>
<p>## Reproduction Steps</p>
<p>Here's a minimal test case</p>
<p>```python
from litestar import Litestar, get
from litestar.middleware.rate_limit import RateLimitConfig
import uvicorn</p>
<p>@get("/api/data")
def get_data() -&gt; dict:
    return {"message": "sensitive data"}</p>
<p>rate_config = RateLimitConfig(rate_limit=("minute", 2))</p>
<p>app = Litestar(
    route_handlers=[get_data],
    middleware=[rate_config.middleware]
)</p>
<p>if __name__ == "__main__":
    uvicorn.run(app, host="0.0.0.0", port=8000)
```</p>
<p>Testing the bypass…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1553"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-59152</id>
    <title>Withdrawn: UBUNTU-CVE-2025-59152</title>
    <updated>2026-10-06T17:38:56.557695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> Ubuntu:25.04: litestar</p>
<p>Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined attackers. Litestar's RateLimitMiddleware uses `cache_key_from_request()` to generate cache keys for rate limiting. When an X-Forwarded-For header is present, the middleware trusts it unconditionally and uses its value as part of the client identifier. Since clients can set arbitrary X-Forwarded-For values, each different spoofed IP creates a separate rate limit bucket. An attacker can rotate through different header values to avoid hitting any single bucket's limit. This affects any Litestar application using RateLimitMiddleware with default settings, which likely includes most applications that implement rate limiting. Version 2.18.0 contains a patch for the vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-59152"/>
  </entry>
</feed>
