Security: rennf93/fastapi-guard
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Path-keyed controls (exclude_paths, endpoint_rate_limits, custom checks) silently stop matching under an ASGI root_path or sub-app mountGHSA-q5f7-443m-w4rq published
Aug 27, 2026 by rennf93Moderate -
WebSocket connections bypass every SecurityMiddleware check, including active IP bansGHSA-63qv-gh36-52qf published
Aug 26, 2026 by rennf93High -
Per-route Authentication Bypass on Deeply Nested ASGI Mounts in `fastapi-guard`GHSA-f2vm-w8gq-h378 published
Aug 12, 2026 by rennf93High -
The regex patched in version 3.0.1 can be bypassed.GHSA-rrf6-pxg8-684g published
Jul 23, 2025 by rennf93High -
ReDoS in fastapi-guard's penetration attempts detectorGHSA-j47q-rc62-w448 published
Jul 7, 2025 by rennf93Low -
Remote Header Injection via X-Forwarded-For ManipulationGHSA-77q8-qmj7-x7pp published
May 5, 2025 by rennf93Low