{"id":"CVE-2026-54283","aliases":["GHSA-82w8-qh3p-5jfq","PYSEC-2026-249"],"url":"https://o3.security/vulnerability/CVE-2026-54283","summary":"Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS","details":"Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data. These limits are enforced for multipart/form-data, but silently ignored for application/x-www-form-urlencoded. An unauthenticated attacker can therefore send a urlencoded body with an arbitrarily large number of fields or an arbitrarily large field, even when the application configured limits it believed would apply. This vulnerability is fixed in 1.3.1.","published":"2026-06-22T16:46:16.706Z","modified":"2026-08-12T03:51:15.699113983Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"starlette","fixedVersion":"1.3.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54283.json"},{"type":"ADVISORY","url":"https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54283"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.699113983Z"}}