Skip to content

Conversation

@defnull
Copy link
Contributor

@defnull defnull commented Oct 16, 2024

Avoid versions affected by CVE-2024-47874

@github-actions
Copy link
Contributor

📝 Docs preview for commit 486a970 at: https://8e9aecfd.fastapitiangolo.pages.dev

@alejsdev alejsdev changed the title Upgrade Starlette to >=0.40.0,<0.41.0 ⬆️ Upgrade Starlette to >=0.40.0,<0.41.0 Oct 17, 2024
@bluppfisk
Copy link

neat :) is there a roadmap when this will be released with a new fastapi version? The CVE severity seems high enough to upgrade right away.

@defnull
Copy link
Contributor Author

defnull commented Oct 18, 2024

You can already upgrade, the current release of FastAPI 'allows' the fixed version of Starlette. But the FastAPI release was not marked as a security release (on purpose), which means that a lot of people may have missed it.

@github-actions
Copy link
Contributor

📝 Docs preview for commit ff248ec at: https://3332f20d.fastapitiangolo.pages.dev

@tiangolo tiangolo changed the title ⬆️ Upgrade Starlette to >=0.40.0,<0.41.0 ⬆️ Upgrade Starlette to >=0.40.0,<0.42.0 Oct 22, 2024
@tiangolo
Copy link
Member

Thanks @defnull! This will be available in FastAPI 0.115.3 in the next hours. 🚀

@tiangolo tiangolo merged commit c4f8143 into fastapi:master Oct 22, 2024
s-rigaud pushed a commit to s-rigaud/fastapi that referenced this pull request Jan 23, 2025
Co-authored-by: Sebastián Ramírez <tiangolo@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants