starlette
Security Risk Profile
35
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 20, 2025 to present
4
Total CVEs
4
Critical+High
0
Exploited
3
Unpatched
Threat Assessment
Avg CVSS
7.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
35/100
low
Severity Distribution
Critical
0High
4Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
SSRF
1
Most Affected Products
1. starlette starlette4
2. npm/fastapi1
3. pip/starlette1
4. IBM Concert Software1
5. open-webui open-webui1
Recent Vulnerabilities
See more →REDHAT-BUG-2490020
CVSS 7.0high
6/17/2026🔧 No Patch
CVE-2025-62727
CVSS 7.5high
Starlette vulnerable to O(n^2) DoS via Range header merging in starlette.responses.FileResponse
10/28/2025
CVE-2024-12868
CVSS 7.5high
Denial of Service through Memory Exhaustion in open-webui/open-webui
3/20/2025🔧 No Patch
CVE-2025-0182
CVSS 7.5high
Denial of Service in danswer-ai/danswer
3/20/2025🔧 No Patch
Monitor starlette in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.