Encode develops a focused portfolio of Python web frameworks and HTTP libraries—notably Starlette, Uvicorn, Django REST Framework, and HTTPX—that are widely embedded in modern API and web-service architectures. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs through input-validation, resource-consumption, code-injection, output-encoding, and path-traversal weaknesses that reflect the parsing and request-handling demands of framework and client libraries. Defenders should track this vendor's releases closely given the framework tier's central role in application stacks; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Encode over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48710MEDIUM Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because | May 26, 2026 | 6.5 | 51 | NO | YES |
CVE-2026-54283HIGH Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_part_size to bound resource consumption while parsing form data | Jun 22, 2026 | 7.5 | 33 | NO | NO |
CVE-2021-41945CRITICAL Encode OSS httpx < 0.23.0 is affected by improper input validation in `httpx.URL`, `httpx.Client` and some functions using `httpx.URL.copy_with`. | Apr 28, 2022 | 9.1 | 33 | NO | NO |
CVE-2026-48818HIGH Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable to SSRF. An UNC path such as \\attacker.com\share can cause o | Jun 17, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-48817MEDIUM Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and look | Jun 17, 2026 | 5.3 | 26 | NO | NO |
CVE-2023-30798HIGH There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or file | Apr 21, 2023 | 7.5 | 26 | NO | NO |
CVE-2026-54282MEDIUM Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebui | Jun 22, 2026 | 5.3 | 25 | NO | NO |
CVE-2020-7694HIGH This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, the | Jul 27, 2020 | 7.5 | 25 | NO | NO |
CVE-2024-24762HIGH `python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including | Feb 5, 2024 | 7.5 | 24 | NO | NO |
CVE-2023-29159HIGH Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built | Jun 1, 2023 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Encode.
Media articles that mention a CVE ID that affects a product developed by Encode — matched by CVE ID, not by vendor name.