peter bassill · operator
$ cve CVE-2026-48710 JSON

CVE-2026-48710 KEV

6.5
MEDIUM · CVSS 3.1 · EPSS 7.1% (pctl 94)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-16.

Description

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS7.06% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-444
On CISA KEVyes — remediate by 2026-09-16
Public exploitnone known
Published2026-05-26
Last modified2026-09-04

CISA KEV

NameKludex Starlette HTTP Request/Response Smuggling Vulnerability
Added2026-09-02
Due2026-09-16
Vendor / productKludex / Starlette
Ransomware usenone reported

Affected (8)

VendorProduct
encodestarlette
redhatai inference server
redhatansible automation platform
redhatenterprise linux ai
redhatmigration toolkit for applications
redhatopenshift ai
redhatopenshift lightspeed
redhatsatellite

References

→ the Explorer  ·  watch your stack  ·  NVD