<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T01:16:43.105060+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-cycode-cve-2025-62727</id>
    <title>BREW-cycode-CVE-2025-62727 — Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``</title>
    <updated>2026-10-04T01:16:43.917528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: cycode</p>
<p>### Summary
An unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's `FileResponse` Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., `StaticFiles` or any use of `FileResponse`).</p>
<p>### Details
Starlette parses multi-range requests in ``FileResponse._parse_range_header()``, then merges ranges using an O(n^2) algorithm.</p>
<p>```python
# starlette/responses.py
_RANGE_PATTERN = re.compile(r"(\d*)-(\d*)") # vulnerable to O(n^2) complexity ReDoS</p>
<p>class FileResponse(Response):
    @staticmethod
    def _parse_range_header(http_range: str, file_size: int) -&gt; list[tuple[int, int]]:
        ranges: list[tuple[int, int]] = []
        try:
            units, range_ = http_range.split("=", 1)
        except ValueError:
            raise MalformedRangeHeader()</p>
<p># [...]</p>
<p>ranges = [
            (
                int(_[0]) if _[0] else file_size - int(_[1]),
                int(_[1]) + 1 if _[0] and _[1] and int(_[1]) &lt; file_size else file_size,
            )
            for _ in _RANGE_PATTERN.findall(range_) # vulnerable
            if _ != ("", "")
        ]</p>
<p>```</p>
<p>The parsing loop of ``FileResponse._parse_range_header()`` uses the regular expression which vulnerable to denial of service for its O(n^2) complexity. A crafted `Range` header can maximize its complexity.</p>
<p>The merge loop processes each input range by scanning the entire resul…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-cycode-cve-2025-62727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-1138</id>
    <title>certfr-2025-avi-1138 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu Platform. Elles permettent à un attaquant de provoque…</title>
    <updated>2026-10-04T01:16:43.917718+00:00</updated>
    <content>certfr-2025-avi-1138</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-1138"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-al63130</id>
    <title>Withdrawn: CLEANSTART-2026-AL63130 — Security fixes in litellm-database 1.96.0-r0</title>
    <updated>2026-10-04T01:16:43.917748+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: litellm-database</p>
<p>Package litellm-database version 1.96.0-r0 fixes 5 vulnerabilities: CVE-2026-54282, CVE-2025-62727, CVE-2026-48818, CVE-2026-54283, CVE-2025-54121</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-al63130"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259072</id>
    <title>EUVD-2026-259072</title>
    <updated>2026-10-04T01:16:43.917783+00:00</updated>
    <content>EUVD-2026-259072</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259072"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-62727</id>
    <title>fkie_cve-2025-62727</title>
    <updated>2026-10-04T01:16:43.917804+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-62727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7f5h-v6xp-fcq8</id>
    <title>GHSA-7f5h-v6xp-fcq8 — Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``</title>
    <updated>2026-10-04T01:16:43.917849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: starlette</p>
<p>### Summary
An unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's `FileResponse` Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., `StaticFiles` or any use of `FileResponse`).</p>
<p>### Details
Starlette parses multi-range requests in ``FileResponse._parse_range_header()``, then merges ranges using an O(n^2) algorithm.</p>
<p>```python
# starlette/responses.py
_RANGE_PATTERN = re.compile(r"(\d*)-(\d*)") # vulnerable to O(n^2) complexity ReDoS</p>
<p>class FileResponse(Response):
    @staticmethod
    def _parse_range_header(http_range: str, file_size: int) -&gt; list[tuple[int, int]]:
        ranges: list[tuple[int, int]] = []
        try:
            units, range_ = http_range.split("=", 1)
        except ValueError:
            raise MalformedRangeHeader()</p>
<p># [...]</p>
<p>ranges = [
            (
                int(_[0]) if _[0] else file_size - int(_[1]),
                int(_[1]) + 1 if _[0] and _[1] and int(_[1]) &lt; file_size else file_size,
            )
            for _ in _RANGE_PATTERN.findall(range_) # vulnerable
            if _ != ("", "")
        ]</p>
<p>```</p>
<p>The parsing loop of ``FileResponse._parse_range_header()`` uses the regular expression which vulnerable to denial of service for its O(n^2) complexity. A crafted `Range` header can maximize its complexity.</p>
<p>The merge loop processes each input range by scanning the entire resul…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7f5h-v6xp-fcq8"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15696-1</id>
    <title>openSUSE-SU-2025:15696-1 — python311-starlette-0.49.1-1.1 on GA media</title>
    <updated>2026-10-04T01:16:43.917986+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python311-starlette-0.49.1-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15696-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1942</id>
    <title>PYSEC-2026-1942 — Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``</title>
    <updated>2026-10-04T01:16:43.918014+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: starlette</p>
<p>### Summary
An unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's `FileResponse` Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., `StaticFiles` or any use of `FileResponse`).</p>
<p>### Details
Starlette parses multi-range requests in ``FileResponse._parse_range_header()``, then merges ranges using an O(n^2) algorithm.</p>
<p>```python
# starlette/responses.py
_RANGE_PATTERN = re.compile(r"(\d*)-(\d*)") # vulnerable to O(n^2) complexity ReDoS</p>
<p>class FileResponse(Response):
    @staticmethod
    def _parse_range_header(http_range: str, file_size: int) -&gt; list[tuple[int, int]]:
        ranges: list[tuple[int, int]] = []
        try:
            units, range_ = http_range.split("=", 1)
        except ValueError:
            raise MalformedRangeHeader()</p>
<p># [...]</p>
<p>ranges = [
            (
                int(_[0]) if _[0] else file_size - int(_[1]),
                int(_[1]) + 1 if _[0] and _[1] and int(_[1]) &lt; file_size else file_size,
            )
            for _ in _RANGE_PATTERN.findall(range_) # vulnerable
            if _ != ("", "")
        ]</p>
<p>```</p>
<p>The parsing loop of ``FileResponse._parse_range_header()`` uses the regular expression which vulnerable to denial of service for its O(n^2) complexity. A crafted `Range` header can maximize its complexity.</p>
<p>The merge loop processes each input range by scanning the entire resul…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1942"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:22759</id>
    <title>RHSA-2025:22759 — Red Hat Security Advisory: RHOAI 2.22.3 - Red Hat OpenShift AI</title>
    <updated>2026-10-04T01:16:43.918149+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keras: Arbitary Code execution in Keras load_model() keras: Keras Path Traversal Vulnerability database/sql: Postgres Scan Race Condition aiohttp: AIOHTTP HTTP Request/Response Smuggling golang: archive/tar: Unbounded allocation when parsing GNU sparse map axios: Axios DoS via lack of data size check github.com/argoproj/argo-workflows: Argo Workflows Zip Slip starlette: Starlette DoS via Range header merging</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:22759"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22151-1</id>
    <title>SUSE-SU-2026:22151-1 — Security update for python-starlette</title>
    <updated>2026-10-04T01:16:43.918197+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-starlette</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22151-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-62727</id>
    <title>UBUNTU-CVE-2025-62727</title>
    <updated>2026-10-04T01:16:43.918224+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:22.04:LTS: starlette, Ubuntu:24.04:LTS: starlette, Ubuntu:25.10: starlette, Ubuntu:26.04:LTS: starlette</p>
<p>Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-62727"/>
  </entry>
</feed>
