GHSA-hm36-ffrh-c77c · Severity: high · Ecosystem: pip — Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In version 2.17.0, rate limits can be completely bypassed by manipulating the X-Forwarded-For header. This renders IP-based rate limiting ineffective against determined attackers. Litestar's RateLimitMiddleware uses `cache_key_from_request()` to generate cache keys for rate limiting. When an X-Forwarded-For header is present, the middleware trusts it unconditionally and uses its value as part of the client identifier. Since clients can set arbitrary X-Forwarded-For values, each different spoofed IP creates a separate rate limit bucket. An attacker can rotate through different header values to avoid hitting any single bucket's limit. This affects any Litestar application using RateLimitMiddleware with default settings, which likely includes most applications that implement rate limiting. Version 2.18.0 contains a patch for the vulnerability.
Conclusion & alert: CVE-2025-59152 is rated Low Risk (35.3/100): CVSS High severity, with low exploitation likelihood (EPSS 0.05%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-07 | — | 0.05% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-hm36-ffrh-c77c · Severity: high · Ecosystem: pip — Litestar X-Forwarded-For Header Spoofing Vulnerability Enables Rate Limit Evasion
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2025-59152 medium priority: Ubuntu including 1 source packages (litestar), 5 status rows across 5 suites (jammy, noble, plucky, questing, upstream): DNE 3, ignored 1, needs-triage 1. | https://ubuntu.com/security/CVE-2025-59152 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||