Записи encode
13 опубликованных записей вендора encode.
Профиль для исследователя
- Попали в KEV
- 1 · 7,7 %
- С эксплойтом
- 1 · 7,7 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- 99 дн.
Повторяющиеся классы
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-20 Improper Input Validation2
- CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')1
- CWE-706 Use of Incorrectly-Resolved Name or Reference1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2026-48710Готовый эксплойт | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checksencode · starlette · CWE-444 | Средняя6,5 | KEV | 7,1 % | 26 мая 2026 г. |
37Наблюдать | CVE-2021-41945Эксплойта нет | Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_wencode · httpx · CWE-20 | Критическая9,1 | — | 2,1 % | 28 апр. 2022 г. |
34Наблюдать | CVE-2024-47874Эксплойта нет | Starlette Denial of service (DoS) via multipart/form-dataencode · starlette · CWE-770 | Высокая8,7 | — | 0,7 % | 15 окт. 2024 г. |
31Наблюдать | CVE-2023-29159Эксплойта нет | Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to vieencode · starlette · CWE-22 | Высокая7,5 | — | 2,0 % | 31 мая 2023 г. |
30Наблюдать | CVE-2024-24762Эксплойта нет | python-multipart vulnerable to content-type header Regular expression Denial of Servicefastapiexpert · python-multipart · CWE-400 | Высокая7,5 | — | 1,5 % | 5 февр. 2024 г. |
30Наблюдать | CVE-2020-7694Эксплойта нет | This affects all versions of package uvicorn.encode · uvicorn · CWE-94 | Высокая7,5 | — | 1,4 % | 27 июл. 2020 г. |
30Наблюдать | CVE-2023-30798Эксплойта нет | MultipartParser DOS with too many fields or files in Starlette Frameworkencode · starlette · CWE-400 | Высокая7,5 | — | 1,3 % | 21 апр. 2023 г. |
30Наблюдать | CVE-2026-48818Эксплойта нет | Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windowsencode · starlette · CWE-918 | Высокая7,5 | — | 0,6 % | 17 июн. 2026 г. |
30Наблюдать | CVE-2026-54283Эксплойта нет | Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSencode · starlette · CWE-770 | Высокая7,5 | — | 0,5 % | 22 июн. 2026 г. |
24Наблюдать | CVE-2020-25626Эксплойта нет | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2.encode · django rest framework · CWE-20 | Средняя6,1 | — | 1,3 % | 30 сент. 2020 г. |
21Наблюдать | CVE-2020-7695Эксплойта нет | HTTP Response Splittingencode · uvicorn · CWE-74 | Средняя5,3 | — | 1,4 % | 27 июл. 2020 г. |
21Наблюдать | CVE-2026-48817Эксплойта нет | Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`encode · starlette · CWE-470 | Средняя5,3 | — | 0,3 % | 17 июн. 2026 г. |
21Наблюдать | CVE-2026-54282Эксплойта нет | Starlette: Unvalidated request path concatenated into authority poisons request.url.hostnameencode · starlette · CWE-706 | Средняя5,3 | — | 0,3 % | 22 июн. 2026 г. |
- CVE-2026-4871058В плане
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 7 %encode · starlette26 мая 2026 г.
- CVE-2021-4194537Наблюдать
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_w
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %encode · httpx28 апр. 2022 г.
- CVE-2024-4787434Наблюдать
Starlette Denial of service (DoS) via multipart/form-data
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %encode · starlette15 окт. 2024 г.
- CVE-2023-2915931Наблюдать
Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to vie
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %encode · starlette31 мая 2023 г.
- CVE-2024-2476230Наблюдать
python-multipart vulnerable to content-type header Regular expression Denial of Service
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %fastapiexpert · python-multipart5 февр. 2024 г.
- CVE-2020-769430Наблюдать
This affects all versions of package uvicorn.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %encode · uvicorn27 июл. 2020 г.
- CVE-2023-3079830Наблюдать
MultipartParser DOS with too many fields or files in Starlette Framework
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %encode · starlette21 апр. 2023 г.
- CVE-2026-4881830Наблюдать
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %encode · starlette17 июн. 2026 г.
- CVE-2026-5428330Наблюдать
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %encode · starlette22 июн. 2026 г.
- CVE-2020-2562624Наблюдать
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %encode · django rest framework30 сент. 2020 г.
- CVE-2020-769521Наблюдать
HTTP Response Splitting
СредняяCVSS 5,3Эксплойта нетEPSS 1 %encode · uvicorn27 июл. 2020 г.
- CVE-2026-4881721Наблюдать
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
СредняяCVSS 5,3Эксплойта нетEPSS 0 %encode · starlette17 июн. 2026 г.
- CVE-2026-5428221Наблюдать
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
СредняяCVSS 5,3Эксплойта нетEPSS 0 %encode · starlette22 июн. 2026 г.