CVE-2026-48710
Description
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP Host request header was not validated before being used to reconstruct request.url. Because the routing algorithm relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header could make request.url.path differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on request.url (rather than the raw scope path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the Host header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing request.url and falls back to scope["server"] for malformed values.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
starlettePyPI | < 1.0.1 | 1.0.1 |
Affected products
12- osv-coords9 versionspkg:apk/chainguard/nemopkg:apk/chainguard/tritonserver-backend-vllm-cuda-12.9pkg:apk/chainguard/wazuh-manager-frameworkpkg:apk/chainguard/wazuh-manager-framework-fipspkg:rpm/opensuse/python-google-adk&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-starlette&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-starlette&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-starlette&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/python-starlette&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 2.7.3-r6+ 8 more
- (no CPE)range: < 2.7.3-r6
- (no CPE)range: < 25.9.0_git20260617-r0
- (no CPE)range: < 4.14.5-r2
- (no CPE)range: < 4.14.5-r3
- (no CPE)range: < 2.2.0-1.1
- (no CPE)range: < 0.41.3-160000.3.1
- (no CPE)range: < 1.2.0-1.1
- (no CPE)range: < 0.41.3-160000.3.1
- (no CPE)range: < 0.41.3-160000.3.1
Patches
Vulnerability mechanics
References
32- github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6nvdPatchWEB
- www.secwest.net/starlettenvdExploitMitigationThird Party AdvisoryWEB
- www.wiz.io/blog/ai-infrastructure-honeypotnvdExploitThird Party Advisory
- www.x41-dsec.de/lab/advisories/x41-2026-002-starlettenvdExploitMitigationThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:22992nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:22993nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:23346nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:24866nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:26226nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:30088nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:30089nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:34456nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:34526nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:34532nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:37275nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:43038nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:44696nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:51357nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:60520nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2026:63337nvdThird Party Advisory
- access.redhat.com/security/cve/CVE-2026-48710nvdThird Party AdvisoryWEB
- badhost.orgnvdMitigationThird Party AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party AdvisoryWEB
- github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mrnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-86qp-5c8j-p5mrghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yamlnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-48710ghsaADVISORY
- ostif.org/disclosing-the-badhost-vulnerability-in-starlettenvdMitigationThird Party AdvisoryWEB
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.jsonnvdThird Party AdvisoryWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdThird Party AdvisoryUS Government Resource
- www.cve.org/CVERecordghsaWEB
- www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-pointsnvdBroken Link
News mentions
11- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin KeyThe Hacker News · Sep 10, 2026
- Sangoma Switchvox Vulnerabilities Exploited in the WildSecurityWeek · Sep 4, 2026
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersThe Hacker News · Sep 3, 2026
- Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key TheftCyber Security News · Aug 28, 2026
- Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine CryptocurrencyCyber Security News · Aug 27, 2026
- When AI infrastructure becomes the target: Securing gateways and control pointsMicrosoft Security Blog · Aug 26, 2026
- LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)Help Net Security · Jun 9, 2026
- Hackers Exploiting LiteLLM RCE Vulnerability in the Wild to Run Arbitrary CommandsCyber Security News · Jun 9, 2026
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCEThe Hacker News · Jun 9, 2026
- Attackers Can Exploit BadHost to Access Sensitive AI Agent Server EndpointsCyber Security News · May 27, 2026
- CISA Adds Seven Known Exploited Vulnerabilities to CatalogCISA Alerts