6.5

CVE-2026-48710

Warnung
Medienbericht
Exploit

Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Encode ≫ Starlette SwPlatform python Version >= 0.8.3 < 1.0.1
Redhat ≫ Ai Inference Server Version >= 3.3.0 <= 3.3.5
Redhat ≫ Ansible Automation Platform Version 2.6 Update -
Redhat ≫ Ansible Automation Platform Version 2.7 Update -
Redhat ≫ Openshift Ai Version >= 3.3 < 3.3.5
Redhat ≫ Openshift Ai Version >= 3.4 < 3.4.2
Redhat ≫ Satellite Version 6.17
Redhat ≫ Satellite Version 6.18
Redhat ≫ Satellite Version 6.19
Redhat ≫ Enterprise Linux Ai Version 3.0

02.09.2026: CISA Known Exploited Vulnerabilities (KEV) Catalog

Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Schwachstelle

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Beschreibung

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.84% 0.767
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
security-advisories@github.com 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 6.5 3.9 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CWE-1289 Improper Validation of Unsafe Equivalence in Input

The product receives an input value that is used as a resource identifier or other type of reference, but it does not validate or incorrectly validates that the input is equivalent to a potentially-unsafe value.

CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
07.10.2026 17:21
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
10.09.2026 11:11
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
03.09.2026 08:36
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
09.06.2026 08:41
https://badhost.org
Third Party Advisory
Mitigation
https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette
Third Party Advisory
Mitigation
https://www.secwest.net/starlette
Third Party Advisory
Exploit
Mitigation
https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette
Third Party Advisory
Exploit
Mitigation
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.json
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2481742
Third Party Advisory
Issue Tracking
https://access.redhat.com/errata/RHSA-2026:30088
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:30089
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:34456
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:34526
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:24866
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:37275
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:26226
Third Party Advisory
https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6
Patch
https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr
Vendor Advisory
https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yaml
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:22992
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:22993
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:23346
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:34532
Third Party Advisory
https://access.redhat.com/security/cve/CVE-2026-48710
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:43038
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:44696
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:51357
Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:60520
Third Party Advisory
https://www.wiz.io/blog/ai-infrastructure-honeypot
Third Party Advisory
Exploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48710
Third Party Advisory
US Government Resource
https:/www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points
Broken Link
https://access.redhat.com/errata/RHSA-2026:63337
Third Party Advisory