Marcelo Trylesinski
9 exploits
Active since Apr 2023
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
CVSS 7.5
Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
CVSS 6.5
Starlette 0.39.0-0.49.0 - Unauthenticated Denial of Service via HTTP Range Header
CVSS 7.5
Starlette < 0.25.0 - Unauthenticated Denial of Service via MultipartParser
CVSS 7.5
Starlette < 0.40.0 - Denial of Service via Unbounded Multipart Form Data Handling
python-multipart < 0.0.18 - Denial of Service via Excessive Logging
CVSS 7.5
Starlette < 0.47.2 - Denial of Service via Large File Upload
CVSS 5.3
Starlette 0.39.0-0.49.0 - Unauthenticated Denial of Service via HTTP Range Header
CVSS 7.5
Python-Multipart <0.0.22 - Path Traversal
CVSS 8.6