starlette-healthchecks@1.3.2
Vulnerability report · Last retrieved from osv.dev October 7, 2026 at 8:32 AM UTC
OSV ID
MAL-2026-16356
Ecosystem
pypi
Summary
The package advertises itself as ASGI healthcheck/logging middleware, but its documented entry point configure_logging() (re-exported from src/starlette_healthcheck/setup.py via __init__.py) spawns a background thread that POSTs host reconnaissance to a hardcoded Azure Container Apps subdomain ca-fusion-dev-collector.victorioussmoke-2f009910.uksouth.azurecontainerapps.io, which the caller does not configure. The beacon iterates the entire os.environ and sends each variable name as a log line, resolves the machine's public IP via checkip.amazonaws.com, and sends the hostname. Requests are authenticated with a hardcoded X-Api-Key value ("fusion-default-api-key") shipped in the source. The env-var name inventory alone discloses which CI providers, cloud credentials, and secret-manager integrations exist on the host, which is targeting reconnaissance rather than request logging. Placing the exfiltration code in a module named setup.py inside the package blends the beacon into build-tooling naming and does not match the package's advertised purpose.
Source: amazon-inspector (eebffb3f581b979c3e9a1dc0aef347111b50922326b2181cc9d2bc009c4e7021)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.