CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
CSIRTS triage
- What
- Starlette contains an HTTP request/response smuggling vulnerability enabling path injection into the host part, potentially bypassing authentication checks.
- Who is affected
- Web applications using Kludex Starlette that rely on URL path-based authentication mechanisms.
- Urgency
- Critical; actively exploited and can be chained with other vulnerabilities for authentication bypass.
- Action
- Update Starlette to a patched version and review authentication logic for path-dependency issues.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Starlette
Get an email when a new Starlette advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-48710
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-48710Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 80% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48710 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds Seven Known Exploited Vulnerabilities to Catalogcisa
- unknownexploitedMultiple vulnerabilities in IBM products (August 28, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- mediumexploitedGHSA-86qp-5c8j-p5mr: Starlette has missing Host header validation that poisons request.url.path, bypassing pat…ghsa
More from CISA Known Exploited Vulnerabilities
- criticalCVE-2026-82329: JFrog Artifactory Improper Authentication Vulnerability2026-09-02
- criticalCVE-2026-83549: SonicWall SMA1000 Appliances OS Command Injection Vulnerability2026-09-02
- criticalCVE-2026-49869: Kestra OSS OS Command Injection Vulnerability2026-09-02
- criticalCVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability2026-09-02
- criticalCVE-2026-83548: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability2026-09-02