Skip to content

[Aikido] Fix critical issue in fastapi via minor version upgrade from 0.128.0 to 0.133.0#25

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-40940063-thap
Open

[Aikido] Fix critical issue in fastapi via minor version upgrade from 0.128.0 to 0.133.0#25
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-40940063-thap

Conversation

@aikido-autofix
Copy link
Copy Markdown
Contributor

Upgrade FastAPI to fix critical Host header validation vulnerability allowing path-based security bypass and authorization middleware circumvention.

✅ 1 CVE resolved by this upgrade, including 1 critical 🚨 CVE

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-10923
🚨 CRITICAL
[starlette] Improper Host header validation allows attackers to craft malicious headers with path or query delimiters, causing request.url.path to diverge from the actual requested path and potentially bypassing path-based security checks or authorization middleware.

@aikido-autofix aikido-autofix Bot added the security Label created by Aikido AutoFix label May 28, 2026
@socket-security
Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedfastapi@​0.128.0 ⏵ 0.133.0100 +1100100100100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Label created by Aikido AutoFix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants