starlette-admin
Fast, beautiful and extensible administrative interface framework for FastApi & Starlette applications
Activity
- Latest release
- 2w ago
- Total releases
- 88
- Cadence
- ~7 days
- Last 12 months
- 12
Reach
- Stars
- 1.0k
Details
- License
- MIT
- First release
- Aug 29, 2022
| Version | Released | |
|---|---|---|
1.0.1
patch
| ||
1.0.0
major
| ||
1.0.0rc5
pre
| ||
1.0.0rc4
pre
| ||
1.0.0rc3
pre
| ||
1.0.0rc2
pre
| ||
1.0.0rc1
pre
| ||
0.17.1
patch
| ||
0.17.0
minor
| ||
0.16.1
patch
| ||
0.16.0
minor
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.16.0rc4
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.16.0rc3
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.16.0rc2
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.16.0rc1
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.16.0rc0
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.1
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0
minor
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc10
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc9
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc8
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc7
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc6
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc5
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc4
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc3
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc1
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.15.0rc0
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.14.1
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.14.0
minor
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.2
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.1
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.0
minor
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.0rc3
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.0rc2
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.13.0rc1
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.2
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.1
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.0
minor
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.0.dev1
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.12.0.dev0
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.2
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.1
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.1.dev0
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.11.0.dev0
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.1
patch
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.10.0.dev0
pre
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2026-54553
PYSEC-2026-3924
GHSA-6753-gr46-6wpr
Sep 10, 2026
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
Low
SummaryAffected versions of Starlette-Admin prior to 0.16.1 do not properly validate user-supplied sort and search parameters against the configured field allowlists. While the administrative UI restricts available fields based on field configuration, the backend accepts arbitrary field names supplied through API requests. An authenticated user can submit crafted requests to sort or filter records using fields that are not intended to be searchable or sortable. Additionally, supplying invalid field names or special Python attribute names can trigger unhandled exceptions that result in HTTP 500 responses. ImpactAn authenticated user with access to affected list endpoints may:
This vulnerability may result in unauthorized use of query functionality and limited denial-of-service conditions affecting the targeted endpoint. Affected VersionsAll versions before 0.16.1. Patched Versions
WorkaroundsThere are no known workarounds. Users should upgrade to version 0.16.1 or later. Affected versions
0.0.1
0.0.2rc0
0.1.0
0.1.1
0.10.0
0.10.0.dev0
0.10.1
0.11.0
0.11.0.dev0
0.11.1
0.11.1.dev0
0.11.2
+ 66 more Show less
0.12.0
0.12.0.dev0
0.12.0.dev1
0.12.1
0.12.2
0.13.0
0.13.0rc1
0.13.0rc2
0.13.0rc3
0.13.1
0.13.2
0.14.0
0.14.1
0.15.0
0.15.0rc0
0.15.0rc1
0.15.0rc10
0.15.0rc3
0.15.0rc4
0.15.0rc5
0.15.0rc6
0.15.0rc7
0.15.0rc8
0.15.0rc9
0.15.1
0.16.0
0.16.0rc0
0.16.0rc1
0.16.0rc2
0.16.0rc3
0.16.0rc4
0.2.0
0.2.1
0.2.2
0.3.0
0.3.0.dev1
0.3.0.dev2
0.3.0.dev3
0.3.0.dev4
0.3.0.dev5
0.3.1
0.3.2
0.3.2.dev0
0.4.0
0.5.0
0.5.0.dev0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.0.dev0
0.6.0.dev1
0.6.0.dev2
0.6.0.dev3
0.6.0.dev4
0.6.0.dev5
0.7.0
0.7.0.dev0
0.8.0
0.8.0.dev0
0.8.1
0.8.2
0.9.0
0.9.0.dev0
Fixed in
0.16.1
References
Updated Sep 10, 2026 · Source: OSV.dev |