DSA-6478-1 starlette - security update
Several vulnerabilities were discovered in starlette, a lightweight ASGI framework/toolkit, which could result in bypass of authorization checks or denial of service. https://security-tracker.debian.org/tracker/DSA-6478-1
CSIRTS triage
- What
- Authorization checks can be bypassed and denial of service conditions triggered in Starlette.
- Who is affected
- Deployments running vulnerable versions of Starlette.
- Urgency
- Moderate urgency; authorization bypass requires prompt patching to prevent access control violations.
- Action
- Apply the security update from Debian DSA-6478-1 or upgrade to a patched version of Starlette.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Starlette
Get an email when a new Starlette advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00389.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-488170.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542820.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-542830.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48817 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54282 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54283 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedMultiple vulnerabilities in IBM products (August 28, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
- lowGHSA-jp82-jpqv-5vv3: Starlette: Unvalidated request path concatenated into authority poisons request.url.hostn…ghsa
- mediumGHSA-x746-7m8f-x49c: Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`ghsa
More from Debian Security Advisories
- unknownDSA-6481-1 firefox-esr - security update2026-09-02
- unknownDSA-6480-1 keystone - security update2026-09-01
- unknownDSA-6479-1 roundcube - security update2026-08-30
- unknownDSA-6477-1 linux - security update2026-08-29
- unknownDSA-6474-1 cockpit - security update2026-08-27