Threats Tagged 'cve-2026-25480'
View all threats tagged with 'cve-2026-25480'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-25480'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-25480 is a medium severity vulnerability in the litestar ASGI framework versions prior to 2.20.0. It arises from improper handling of Unicode normalization in the FileStore cache backend, which maps cache keys to filenames using Unicode NFKD normalization and ord() substitution without separators. This flawed approach can cause cache key collisions when an unauthenticated remote attacker crafts specific URL paths, leading to cache poisoning or response mixups where one URL serves cached responses intended for another. The vulnerability does not require authentication or user interaction and impacts confidentiality and integrity by exposing or mixing cached data. It is fixed in litestar version 2.20.0. European organizations using vulnerable litestar versions as part of their web infrastructure may face risks of data leakage or incorrect content delivery. Join the discussion | CVE Database V5 | 02/09/2026, 18:49:34 UTC Added: 02/09/2026, 19:31:19 UTC |
Showing 1 to 1 of 1 result