Skip to content
Noroxi

encode records

13 published records for vendor encode.

All records

13 records
  • Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

    MediumCVSS 6.5KEVWeaponizedEPSS 7%

    encode · starletteMay 26, 2026

  • Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_w

    CriticalCVSS 9.1No exploitEPSS 2%

    encode · httpxApr 28, 2022

  • Starlette Denial of service (DoS) via multipart/form-data

    HighCVSS 8.7No exploitEPSS 1%

    encode · starletteOct 15, 2024

  • Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to vie

    HighCVSS 7.5No exploitEPSS 2%

    encode · starletteMay 31, 2023

  • python-multipart vulnerable to content-type header Regular expression Denial of Service

    HighCVSS 7.5No exploitEPSS 2%

    fastapiexpert · python-multipartFeb 5, 2024

  • CVE-2020-7694
    30Monitor

    This affects all versions of package uvicorn.

    HighCVSS 7.5No exploitEPSS 1%

    encode · uvicornJul 27, 2020

  • MultipartParser DOS with too many fields or files in Starlette Framework

    HighCVSS 7.5No exploitEPSS 1%

    encode · starletteApr 21, 2023

  • Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

    HighCVSS 7.5No exploitEPSS 1%

    encode · starletteJun 17, 2026

  • Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS

    HighCVSS 7.5No exploitEPSS 0%

    encode · starletteJun 22, 2026

  • A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2.

    MediumCVSS 6.1No exploitEPSS 1%

    encode · django rest frameworkSep 30, 2020

  • CVE-2020-7695
    21Monitor

    HTTP Response Splitting

    MediumCVSS 5.3No exploitEPSS 1%

    encode · uvicornJul 27, 2020

  • Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`

    MediumCVSS 5.3No exploitEPSS 0%

    encode · starletteJun 17, 2026

  • Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname

    MediumCVSS 5.3No exploitEPSS 0%

    encode · starletteJun 22, 2026