encode records
13 published records for vendor encode.
Researcher profile
- Entered KEV
- 1 · 7.7%
- Weaponized
- 1 · 7.7%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- 99 days
Recurring classes
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-20 Improper Input Validation2
- CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')1
- CWE-706 Use of Incorrectly-Resolved Name or Reference1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2026-48710Weaponized | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checksencode · starlette · CWE-444 | Medium6.5 | KEV | 7.1% | May 26, 2026 |
37Monitor | CVE-2021-41945No exploit | Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_wencode · httpx · CWE-20 | Critical9.1 | — | 2.1% | Apr 28, 2022 |
34Monitor | CVE-2024-47874No exploit | Starlette Denial of service (DoS) via multipart/form-dataencode · starlette · CWE-770 | High8.7 | — | 0.7% | Oct 15, 2024 |
31Monitor | CVE-2023-29159No exploit | Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to vieencode · starlette · CWE-22 | High7.5 | — | 2.0% | May 31, 2023 |
30Monitor | CVE-2024-24762No exploit | python-multipart vulnerable to content-type header Regular expression Denial of Servicefastapiexpert · python-multipart · CWE-400 | High7.5 | — | 1.5% | Feb 5, 2024 |
30Monitor | CVE-2020-7694No exploit | This affects all versions of package uvicorn.encode · uvicorn · CWE-94 | High7.5 | — | 1.4% | Jul 27, 2020 |
30Monitor | CVE-2023-30798No exploit | MultipartParser DOS with too many fields or files in Starlette Frameworkencode · starlette · CWE-400 | High7.5 | — | 1.3% | Apr 21, 2023 |
30Monitor | CVE-2026-48818No exploit | Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windowsencode · starlette · CWE-918 | High7.5 | — | 0.6% | Jun 17, 2026 |
30Monitor | CVE-2026-54283No exploit | Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSencode · starlette · CWE-770 | High7.5 | — | 0.5% | Jun 22, 2026 |
24Monitor | CVE-2020-25626No exploit | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2.encode · django rest framework · CWE-20 | Medium6.1 | — | 1.3% | Sep 30, 2020 |
21Monitor | CVE-2020-7695No exploit | HTTP Response Splittingencode · uvicorn · CWE-74 | Medium5.3 | — | 1.4% | Jul 27, 2020 |
21Monitor | CVE-2026-48817No exploit | Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`encode · starlette · CWE-470 | Medium5.3 | — | 0.3% | Jun 17, 2026 |
21Monitor | CVE-2026-54282No exploit | Starlette: Unvalidated request path concatenated into authority poisons request.url.hostnameencode · starlette · CWE-706 | Medium5.3 | — | 0.3% | Jun 22, 2026 |
- CVE-2026-4871058Plan
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
MediumCVSS 6.5KEVWeaponizedEPSS 7%encode · starletteMay 26, 2026
- CVE-2021-4194537Monitor
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_w
CriticalCVSS 9.1No exploitEPSS 2%encode · httpxApr 28, 2022
- CVE-2024-4787434Monitor
Starlette Denial of service (DoS) via multipart/form-data
HighCVSS 8.7No exploitEPSS 1%encode · starletteOct 15, 2024
- CVE-2023-2915931Monitor
Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to vie
HighCVSS 7.5No exploitEPSS 2%encode · starletteMay 31, 2023
- CVE-2024-2476230Monitor
python-multipart vulnerable to content-type header Regular expression Denial of Service
HighCVSS 7.5No exploitEPSS 2%fastapiexpert · python-multipartFeb 5, 2024
- CVE-2020-769430Monitor
This affects all versions of package uvicorn.
HighCVSS 7.5No exploitEPSS 1%encode · uvicornJul 27, 2020
- CVE-2023-3079830Monitor
MultipartParser DOS with too many fields or files in Starlette Framework
HighCVSS 7.5No exploitEPSS 1%encode · starletteApr 21, 2023
- CVE-2026-4881830Monitor
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
HighCVSS 7.5No exploitEPSS 1%encode · starletteJun 17, 2026
- CVE-2026-5428330Monitor
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
HighCVSS 7.5No exploitEPSS 0%encode · starletteJun 22, 2026
- CVE-2020-2562624Monitor
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2.
MediumCVSS 6.1No exploitEPSS 1%encode · django rest frameworkSep 30, 2020
- CVE-2020-769521Monitor
HTTP Response Splitting
MediumCVSS 5.3No exploitEPSS 1%encode · uvicornJul 27, 2020
- CVE-2026-4881721Monitor
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
MediumCVSS 5.3No exploitEPSS 0%encode · starletteJun 17, 2026
- CVE-2026-5428221Monitor
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
MediumCVSS 5.3No exploitEPSS 0%encode · starletteJun 22, 2026