Skip to content

Conversation

@RinZ27
Copy link

@RinZ27 RinZ27 commented Jan 17, 2026

I was reviewing the dependencies and noticed that starlette is pinned to a version >=0.27 for older Python versions. This range includes versions vulnerable to CVE-2024-47874, which is a denial-of-service issue related to multipart parsing.

I've updated the constraint to >=0.40.0 to ensure that even users on older Python versions get the security fix. This seemed like a straightforward way to close that potential vulnerability window.

@RinZ27 RinZ27 force-pushed the fix/bump-starlette branch from 5372747 to 980a9de Compare January 17, 2026 14:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant