Junglewise Threat Intelligence

CVE-2026-48710: Starlette auth bypass via malformed Host header

CVE-2026-48710 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2026-05-26

Technologies: starlette (PyPI), Kludex Starlette. Vendors: PyPI, Kludex.

Executive brief

Kludex Starlette, a popular Python web framework library, contains a HTTP request/response smuggling vulnerability that allows attackers to manipulate HTTP headers and inject malicious path information. By exploiting this flaw, an attacker can bypass authentication mechanisms that rely on URL path validation, potentially gaining unauthorized access to protected resources or performing actions on behalf of authenticated users.

Technical details

This is a HTTP request/response smuggling vulnerability in Kludex Starlette that arises from improper handling of HTTP headers when reconstructing request paths and URLs. The vulnerability allows an attacker to inject malicious path information into the host header portion of an HTTP request, causing the server to misinterpret the request path. Since authentication decisions may be based on the reconstructed URL path, an attacker can craft requests that bypass path-based authentication checks. The attack vector is network-based and requires no authentication or special privileges. The vulnerability has been observed in active exploitation in the wild. A patch or mitigation is recommended, and this issue may compound with CVE-2026-42271 for more severe impacts.

Affected products

  • Kludex Starlette

Timeline

  • 2026-09-02: disclosed
  • exploited: Confirmed exploitation in the wild

Related threats