CVE-2025-62727: Kludex Starlette
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range parsing/merging logic. This enables CPU exhaustion per request, causing denial‑of‑service for endpoints serving files (e.g., StaticFiles or any use of FileResponse). This vulnerability is fixed in 0.49.1.
Affected products
- Kludex Starlette: from 0.39.0, before 0.49.1 (fixed in 0.49.1)
Published 2025-10-28. Last modified 2026-10-08.