Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlettes FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat AI Inference Server 3.2 | RedHat | rhaiis/vllm-cuda-rhel9:3.2.2-1765379088 | * |
| Red Hat AI Inference Server 3.2 | RedHat | rhaiis/vllm-rocm-rhel9:3.2.2-1765379049 | * |
| Red Hat AI Inference Server 3.2 | RedHat | rhaiis/model-opt-cuda-rhel9:3.2.2-1764871796 | * |
| Red Hat AI Inference Server 3.2 | RedHat | rhaiis/vllm-cuda-rhel9:1772160593 | * |
| Red Hat AI Inference Server 3.2 | RedHat | rhaiis/vllm-rocm-rhel9:1772160625 | * |
| Red Hat Ansible Automation Platform 2.5 | RedHat | ansible-automation-platform-25/lightspeed-chatbot-rhel8:2.5.251203 | * |
| Red Hat Ansible Automation Platform 2.6 | RedHat | ansible-automation-platform-26/lightspeed-chatbot-rhel9:2.6 | * |
| Red Hat Ansible Automation Platform 2.6 | RedHat | ansible-automation-platform-26/mcp-tools-rhel9:2.6 | * |
| Red Hat OpenShift AI 2.22 | RedHat | rhoai/odh-feature-server-rhel9:v2.22.3-1763565765 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-built-in-detector-rhel9:v2.25.1-1764757773 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-caikit-nlp-rhel9:v2.25.1-1764835788 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-caikit-tgis-serving-rhel9:v2.25.1-1764864501 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-feature-server-rhel9:v2.25.1-1765354568 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-guardrails-detector-huggingface-runtime-rhel9:v2.25.1-1764757773 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-kserve-agent-rhel9:v2.25.1-1765613316 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-kserve-controller-rhel9:v2.25.1-1765613316 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-kserve-router-rhel9:v2.25.1-1765613316 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-kserve-storage-initializer-rhel9:v2.25.1-1765326513 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-llama-stack-core-rhel9:0.0-1763988459 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-vllm-cpu-rhel9:v2.25.1-1765450855 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-vllm-cuda-rhel9:v2.25.1-1765556017 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-vllm-gaudi-rhel9:v2.25.1-1764880438 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-vllm-rocm-rhel9:v2.25.1-1765400024 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat OpenShift AI 2.25 | RedHat | rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:v2.25.1-1764961121 | * |
| Red Hat Satellite 6.18 | RedHat | satellite/foreman-mcp-server-rhel9:1780492008 | * |
| Starlette | Ubuntu | plucky | * |