CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
CSIRTS triage
- What
- Starlette contains an HTTP request/response smuggling vulnerability enabling path injection into the host part, potentially bypassing authentication checks.
- Who is affected
- Web applications using Kludex Starlette that rely on URL path-based authentication mechanisms.
- Urgency
- Critical; actively exploited and can be chained with other vulnerabilities for authentication bypass.
- Action
- Update Starlette to a patched version and review authentication logic for path-dependency issues.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Starlette
Get an email when a new Starlette advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-48710
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-48710Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 98% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48710 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa
- unknownexploitedMultiples vulnérabilités dans les produits IBM (28 août 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- mediumexploitedGHSA-86qp-5c8j-p5mr: Starlette has missing Host header validation that poisons request.url.path, bypassing pat…ghsa
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability2026-09-11
- criticalCVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability2026-09-11
- criticalCVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability2026-09-11
- criticalCVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerabilit…2026-09-11
- criticalCVE-2026-86060: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability2026-09-10