Starlette Vulnerability Fixed; Allows Authentication Bypass (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Authentication bypass in Starlette due to Host header path validation flaw
- Affects FastAPI and other applications using Starlette
- NCSC advisory recommends updating to patched version
"The Dutch NCSC published an advisory about a fixed vulnerability in Starlette, a Python web services library. An unauthenticated attacker can bypass authentication and access protected URL paths. The issue affects FastAPI and other Starlette-based products. Impact depends on the data processed by the vulnerable service."
no comments yet.