CVE-2025-54121
MediumAdvisory
Published 21 Jul 2025In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.006
- 45th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 104
- of 17,781 indexed, latest versions
- Container images
- 129
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Starlette has possible denial-of-service vector when parsing large files in multipart forms
Carried by container images the latest versions of 104 of 17,781 indexed charts deploy, on 129 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| starlettepypi | 0.13.6, 0.13.8, 0.14.1, 0.14.2+23 more | 0.47.2 | 129 |
- OSV records
- GHSA-2c2j-9gv5-cj73
- Also known as
- PYSEC-2026-1941
Charts affected
104 by stars
Container images carrying it
129 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.