• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-48710: host header validation bypass in Kludex Starlette

An unauthenticated remote attacker can send crafted HTTP requests to Kludex Starlette and cause the framework to rebuild request.url from an unvalidated Host header, allowing middleware or endpoints that rely on the reconstructed URL to be bypassed. This issue is tracked as CVE-2026-48710 and affects Starlette releases earlier than 1.0.1. An attacker only needs network access to the affected application to supply a malformed Host header; no credentials or user interaction are required.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
6.5MEDIUM
EPSS
0.07056
CWE
CWE-444
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added CVE-2026-48710 to its Known Exploited Vulnerabilities catalog with a remediation deadline, so prioritize mitigating internet-exposed Starlette instances now and follow vendor guidance.

What is CVE-2026-48710?

An unauthenticated remote attacker can send crafted HTTP requests to Kludex Starlette and cause the framework to rebuild request.url from an unvalidated Host header, allowing middleware or endpoints that rely on the reconstructed URL to be bypassed. This issue is tracked as CVE-2026-48710 and affects Starlette releases earlier than 1.0.1. An attacker only needs network access to the affected application to supply a malformed Host header; no credentials or user interaction are required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Which versions of Kludex Starlette are affected?

BRANCHAFFECTEDFIXED
starlette< 1.0.1

Is CVE-2026-48710 being exploited?

CISA added CVE-2026-48710 to the Known Exploited Vulnerabilities catalog on 2026-09-02 and required mitigations by 2026-09-16 for U.S. federal agencies; public exploit code is also available.

How to fix CVE-2026-48710

  1. Restrict internet exposure of Starlette applications and block untrusted Host header values at the network or proxy layer.
  2. Apply vendor guidance and mitigations immediately and monitor for vendor updates that provide a fixed release.
  3. Log and alert on requests with malformed or unusually long Host headers and investigate related traffic patterns.
  4. Use an ingress proxy or WAF to validate Host headers against expected hostnames before forwarding requests to Starlette.

Frequently asked questions

Is CVE-2026-48710 being actively exploited?

CVE-2026-48710 is listed in CISA’s Known Exploited Vulnerabilities catalog (added 2026-09-02) with a remediation deadline of 2026-09-16 for federal agencies, and public exploit code is available.

Which Starlette versions are affected by CVE-2026-48710?

Starlette releases earlier than 1.0.1 are affected by CVE-2026-48710.

Is there a patch for CVE-2026-48710?

A vendor patch was not listed as available in the supplied facts; follow Kludex guidance and apply mitigations while monitoring for a fixed release.

Does CVE-2026-48710 require authentication?

No, CVE-2026-48710 does not require authentication or user interaction; an unauthenticated remote attacker can supply a crafted Host header.

References