Litestar是Litestar开源的一个强大、灵活但固执己见的 ASGI 框架。 Litestar 2.20.0之前版本存在安全漏洞,该漏洞源于正则表达式元字符未转义,可能导致恶意源意外匹配。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| litestar-org | litestar | < 2.20.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-25480 | 6.5 MEDIUM | FileStore key canonicalization collisions allow response cache mixup/poisoning (ASCII ord |
| CVE-2026-25479 | 6.5 MEDIUM | Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in co |
No comments yet