encode kayıtları
encode üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %7,7
- Silahlaştırılmış
- 1 · %7,7
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- 99 gün
Tekrar eden sınıflar
- CWE-770 Allocation of Resources Without Limits or Throttling2
- CWE-400 Uncontrolled Resource Consumption2
- CWE-20 Improper Input Validation2
- CWE-470 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')1
- CWE-706 Use of Incorrectly-Resolved Name or Reference1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2026-48710Silahlaştırılmış | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checksencode · starlette · CWE-444 | Orta6,5 | KEV | %7,1 | 26 May 2026 |
37İzleyin | CVE-2021-41945İstismar yok | Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_wencode · httpx · CWE-20 | Kritik9,1 | — | %2,1 | 28 Nis 2022 |
34İzleyin | CVE-2024-47874İstismar yok | Starlette Denial of service (DoS) via multipart/form-dataencode · starlette · CWE-770 | Yüksek8,7 | — | %0,7 | 15 Eki 2024 |
31İzleyin | CVE-2023-29159İstismar yok | Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to vieencode · starlette · CWE-22 | Yüksek7,5 | — | %2,0 | 31 May 2023 |
30İzleyin | CVE-2024-24762İstismar yok | python-multipart vulnerable to content-type header Regular expression Denial of Servicefastapiexpert · python-multipart · CWE-400 | Yüksek7,5 | — | %1,5 | 5 Şub 2024 |
30İzleyin | CVE-2020-7694İstismar yok | This affects all versions of package uvicorn.encode · uvicorn · CWE-94 | Yüksek7,5 | — | %1,4 | 27 Tem 2020 |
30İzleyin | CVE-2023-30798İstismar yok | MultipartParser DOS with too many fields or files in Starlette Frameworkencode · starlette · CWE-400 | Yüksek7,5 | — | %1,3 | 21 Nis 2023 |
30İzleyin | CVE-2026-48818İstismar yok | Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windowsencode · starlette · CWE-918 | Yüksek7,5 | — | %0,6 | 17 Haz 2026 |
30İzleyin | CVE-2026-54283İstismar yok | Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSencode · starlette · CWE-770 | Yüksek7,5 | — | %0,5 | 22 Haz 2026 |
24İzleyin | CVE-2020-25626İstismar yok | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2.encode · django rest framework · CWE-20 | Orta6,1 | — | %1,3 | 30 Eyl 2020 |
21İzleyin | CVE-2020-7695İstismar yok | HTTP Response Splittingencode · uvicorn · CWE-74 | Orta5,3 | — | %1,4 | 27 Tem 2020 |
21İzleyin | CVE-2026-48817İstismar yok | Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`encode · starlette · CWE-470 | Orta5,3 | — | %0,3 | 17 Haz 2026 |
21İzleyin | CVE-2026-54282İstismar yok | Starlette: Unvalidated request path concatenated into authority poisons request.url.hostnameencode · starlette · CWE-706 | Orta5,3 | — | %0,3 | 22 Haz 2026 |
- CVE-2026-4871058Planlayın
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %7encode · starlette26 May 2026
- CVE-2021-4194537İzleyin
Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_w
KritikCVSS 9,1İstismar yokEPSS %2encode · httpx28 Nis 2022
- CVE-2024-4787434İzleyin
Starlette Denial of service (DoS) via multipart/form-data
YüksekCVSS 8,7İstismar yokEPSS %1encode · starlette15 Eki 2024
- CVE-2023-2915931İzleyin
Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to vie
YüksekCVSS 7,5İstismar yokEPSS %2encode · starlette31 May 2023
- CVE-2024-2476230İzleyin
python-multipart vulnerable to content-type header Regular expression Denial of Service
YüksekCVSS 7,5İstismar yokEPSS %2fastapiexpert · python-multipart5 Şub 2024
- CVE-2020-769430İzleyin
This affects all versions of package uvicorn.
YüksekCVSS 7,5İstismar yokEPSS %1encode · uvicorn27 Tem 2020
- CVE-2023-3079830İzleyin
MultipartParser DOS with too many fields or files in Starlette Framework
YüksekCVSS 7,5İstismar yokEPSS %1encode · starlette21 Nis 2023
- CVE-2026-4881830İzleyin
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
YüksekCVSS 7,5İstismar yokEPSS %1encode · starlette17 Haz 2026
- CVE-2026-5428330İzleyin
Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
YüksekCVSS 7,5İstismar yokEPSS %0encode · starlette22 Haz 2026
- CVE-2020-2562624İzleyin
A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2.
OrtaCVSS 6,1İstismar yokEPSS %1encode · django rest framework30 Eyl 2020
- CVE-2020-769521İzleyin
HTTP Response Splitting
OrtaCVSS 5,3İstismar yokEPSS %1encode · uvicorn27 Tem 2020
- CVE-2026-4881721İzleyin
Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`
OrtaCVSS 5,3İstismar yokEPSS %0encode · starlette17 Haz 2026
- CVE-2026-5428221İzleyin
Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
OrtaCVSS 5,3İstismar yokEPSS %0encode · starlette22 Haz 2026