← All Advisories

CVE-2026-48710: Kludex Starlette HTTP

Status: KEV  |  Advisory ID: CVE-2026-48710

Key Details

CVECVE-2026-48710
CVSSCVSS 6.5 (Medium).
Affected productssee table below
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-02.
Exploitation prediction (EPSS)36% probability of exploitation in the next 30 days (98% percentile) -- FIRST.org's EPSS model.

What to Know

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-48710
Vendor advisoryhttps://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr