CVE-2024-47874 - CVE House
Back to Database
Status published High CVE-2024-47874

Starlette Denial of service (DoS) via multipart/form-data

Vulnerability Description

Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and buffers those in byte strings with no size limit. This allows an attacker to upload arbitrary large form fields and cause Starlette to both slow down significantly due to excessive memory allocations and copy operations, and also consume more and more memory until the server starts swapping and grinds to a halt, or the OS terminates the server process with an OOM error. Uploading multiple such requests in parallel may be enough to render a service practically unusable, even if reasonable request size limits are enforced by a reverse proxy in front of Starlette. This Denial of service (DoS) vulnerability affects all applications built with Starlette (or FastAPI) accepting form requests. Verison 0.40.0 fixes this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47874

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

starlette
Vulnerable Versions:
< 0.40.0

Timeline

Official Publish: October 15th, 2024
Last Modified: November 21st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)