CNNVD-202602-1298 Information

CNNVD ID

CNNVD-202602-1298

CVE-2026-25480

  • CNNVD Published: 2026-02-09

Description (Chinese)

Litestar是Litestar开源的一个强大、灵活但固执己见的 ASGI 框架。 Litestar 2.20.0之前版本存在安全漏洞,该漏洞源于缓存键映射方式存在键冲突,可能导致缓存投毒或混淆。

Description (English)

Litestar is a powerful, flexible but adamant ASGI framework for Litestar’s open source. There was a security loophole in the previous version of Litestar 2.20.0, which stemmed from a key conflict in the cache key map, which could lead to a cache poisoning or confusion.

Vulnerability Type

其他

Affected Vendor

Litestar

Published

2026-02-09

Last Modified

2026-02-24

References

https://docs.litestar.dev/2/release-notes/changelog.html#2.20.0 https://github.com/litestar-org/litestar/security/advisories/GHSA-vxqx-rh46-q2pg https://github.com/litestar-org/litestar/commit/85db6183a76f8a6b3fd6ee3c88d860b9f37a2cca https://github.com/litestar-org/litestar/releases/tag/v2.20.0 https://access.redhat.com/security/cve/cve-2026-25480

Patch

https://github.com/litestar-org/litestar/releases

Share on: