Hidden link you should not click

CVE-2024-47874 - Starlette/FastAPI

I'm finally allowed to speak about this nice little DoS vulnerability I found in starlette (and FastAPI).

The FastAPI devs published an update 3 days before the security release of Starlette that widened the version range of the dependency just enough to allow the to-be-released patch. Sneaky!