Tiangolo maintains FastAPI, a widely adopted Python web framework for building high-performance REST APIs, with a focused vulnerability profile centered on the framework's request-handling and validation mechanisms. Observed weakness classes in the vendor's disclosures cluster around cross-site request forgery, inefficient regular expression complexity, and uncontrolled resource consumption—patterns typical of web application frameworks exposed to untrusted input and high-volume request scenarios. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tiangolo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24762HIGH `python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including | Feb 5, 2024 | 7.5 | 24 | NO | NO |
CVE-2021-32677HIGH FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path o | Jun 9, 2021 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tiangolo.
Media articles that mention a CVE ID that affects a product developed by Tiangolo — matched by CVE ID, not by vendor name.