FastAPI
PyPIfastapiFastAPI is the most popular Python web framework for building REST and async APIs, used extensively for LLM API wrappers, ML model serving, and microservices. It is built on Starlette and Pydantic and runs under ASGI servers such as Uvicorn or Gunicorn with Uvicorn workers. Its adoption in AI backend services accelerated rapidly after 2022.
Checking FastAPI
fastapi 0.115.0 is a clean, monitored version with no known supply chain compromise. The example response returns supply_chain_monitored: true and compromised: false with an empty sources array.
curl "https://api.attestd.io/v1/check?product=fastapi&version=0.115.0" \
-H "Authorization: Bearer YOUR_API_KEY"{
"product": "fastapi",
"version": "0.115.0",
"supported": true,
"risk_state": "none",
"risk_factors": [],
"actively_exploited": false,
"remote_exploitable": false,
"authentication_required": false,
"patch_available": false,
"fixed_version": null,
"confidence": 0.9,
"cve_ids": [],
"cves": null,
"max_epss": null,
"typosquat": null,
"supply_chain_monitored": true,
"supply_chain": {
"compromised": false,
"sources": [],
"malware_type": null,
"description": null,
"advisory_url": null,
"compromised_at": null,
"removed_at": null
},
"last_updated": "2026-05-01T00:00:00Z"
}Why this package is monitored
FastAPI sits under every ASGI route, including LLM wrappers and model-serving APIs. A poisoned build sees request bodies, auth headers, and dependency-injected credentials before route handlers run.
Attestd monitors fastapi using the following detection sources:
registryManually curated advisories in the Attestd registry, verified by a human analyst. Confidence 1.0.
osvOSV.dev malicious-package advisories with IDs prefixed MAL-. Confidence 0.95.
pypi_yankVersions yanked on PyPI with a security-related yanked_reason annotation. Confidence 0.80.