Executive brief
Starlette is a popular toolkit used by developers to build web services in Python. A flaw in how it handles web addresses allows an attacker to send a specially crafted request that tricks the system into misidentifying which website or server the request is intended for. This could lead to security bypasses in custom software that relies on this information for making security decisions, such as verifying where a user is being redirected.
Technical details
A vulnerability exists in Starlette's URL reconstruction logic where the HTTP request path is concatenated with the scheme and host without proper validation. If an attacker provides a path that does not start with a forward slash (e.g., '@attacker.com'), the re-parsing of the resulting URL string moves the authority boundary, causing 'request.url.hostname' to be controlled by the attacker rather than reflecting the actual 'Host' header. This requires an ASGI server that passes malformed request targets into the 'scope'. Exploitation is primarily limited to middleware or exception handlers that process 'request.url' before routing, as these malformed paths typically result in a 404 error. The issue is resolved in version 1.3.0.
Affected products
- Kludex Starlette < 1.3.0
Timeline
- 2026-06-11: advisory: GitHub Security Advisory published by Kludex
- 2026-06-22: disclosed: CVE published to NVD