CVE-2026-48710
Published May 26, 2026
Last updated 16 days ago
- Description
- Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- starlette, ai_inference_server, ansible_automation_platform, migration_toolkit_for_applications, openshift_ai, openshift_lightspeed, satellite, enterprise_linux_ai
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 2.5
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Exploit added on
- Sep 2, 2026
- Exploit action due
- Sep 16, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Hype score
- Not currently trending
The Starlette flaw (CVE-2026-48710) affects FastAPI and vLLM deployments. Dependency auditing must always check transitive components in AI stacks. #FastAPI #CVE #vLLM #WebDev
@Nishanth_KJ
20 Sept 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-48710 (CVSS 6.5): Starlette BadHost Host Header Auth Bypass Critical Vulnerability Alert! Kludex Starlette is affected by CVE-2026-48710. 🔍 Identify Targets via ZoomEye: Search Dork: http.body="Starlette" Exposure: 1.2k instances identified globally. ZoomEye
@zoomeyebot
16 Sept 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV: attackers are chaining CVE-2026-59822 (LiteLLM MCP auth bypass) with CVE-2026-48710 (Starlette host header) for unauthenticated RCE on AI gateways. Qilin ransomware linked. Federal patch deadline Sept 16. Inventory your AI gateways. #InfoSec #ZeroDay #AISecurity
@infrasecserv
7 Sept 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
Starlette BadHost (CVE-2026-48710): a malformed Host header desyncs the path middleware sees from the routed path, bypassing auth on FastAPI, vLLM, LiteLLM, MCP servers. Check request.scope["path"], not request.url.path. https://t.co/oA8c5Cql8C
@swif_ai
7 Sept 2026
33 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV, Sep 2: 7 new exploited flaws, and AI infrastructure is the target. Microsoft and Wiz tie the LiteLLM chain (CVE-2026-42271 + CVE-2026-48710) to Qilin ransomware, XMRig miners, and stolen upstream provider keys. Your AI gateway is a control plane. #InfoSec #AISecurity
@infrasecserv
6 Sept 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-48710: Starlette \"BadHost\" Request Smuggling Vulnerability Technical analysis of CVE-2026-48710, an HTTP request smuggling flaw in Kludex Starlette enabling authentication bypass via Host header… Full write-up → link in bio #cybersecurity #infosec #cve #kev #klud
@HotaSamit
4 Sept 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性7件をカタログに追加 #CISA (Sep 2) CVE-2026-9586 Sangoma SwitchvoxのSQLインジェクション脆弱性 CVE-2026-48710 Kludex Starlette HTTPリクエスト/レスポンスの密輸脆弱性 CVE-2026-49869 Kestra OSS OSのコマ
@foxbook
3 Sept 2026
263 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-48710: Starlette HTTP Request/Response Smuggling Now in CISA KEV — Det… "On September 2, 2026, CISA added CVE-2026-48710 to the Known Exploited…" 🔗 https://t.co/Xl67paQA4N #CyberSecurity #ThreatIntel #cve202648710 #critical #cisakev
@SecurityAr58409
3 Sept 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-09-02 CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVSS 8.7 · EPSS 2.1% · 13 public exploits Details, versions & intel → https://t.co/l9zAtbJF29 https://t.co/3Ifjvf9mX1
@notCVE
2 Sept 2026
89 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
LiteLLM AI Gatewayの脆弱性CVE-2026-42271について。6/9にサイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログ採録。単体ではAPIキーが必要なコマンドインジェクションだが、CVE-2026-48710
@__kokumoto
23 Jun 2026
469 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CVE-2026-42271: LiteLLM 1.74.2-1.83.6 command injection via MCP test endpoints allows arbitrary OS cmd execution with a valid API key. Fixed in 1.83.7. Chains w/ CVE-2026-48710 for unauthenticated RCE. CISA KEV. Patch now and rotate credentials. #litellm #CVE202642271
@GreyZoneSec
12 Jun 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 LiteLLM CVE-2026-42271 is exploited in the wild. This AI gateway flaw can allow command execution and may chain with Starlette CVE-2026-48710 to become unauthenticated RCE. https://t.co/wdAnqOmrft #CyberSecurity #LiteLLM #AISecurity #RCE #Vulert
@vulert_official
11 Jun 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 New critical LiteLLM flaw is being exploited in the wild. CVE-2026-42271 (CVSS 8.7) — command injection via two MCP preview endpoints. Chained with CVE-2026-48710 (Starlette host header bypass) → unauthenticated RCE (CVSS 10.0). If you run litellm-proxy: read this thre
@456c6f727269
11 Jun 2026
66 Impressions
0 Retweets
0 Likes
1 Bookmark
1 Reply
0 Quotes
LiteLLMのコマンドインジェクションCVE-2026-42271(CVSS 8.7)が悪用されCISAがKEVに追加。StarletteのCVE-2026-48710と連鎖で認証不要RCE、複合CVSS 10.0に。要1.83.7更新 / LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated R
@__su888
9 Jun 2026
72 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Critical Security Advisory LiteLLM Remote Code Execution CVE-2026-42271 and CVE-2026-48710 Threat Intelligence Alert https://t.co/pKGbT7Ml4F #appsec
@eyalestrin
9 Jun 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔐CVE-2026-42271: Critical command injection in LiteLLM AI gateway — actively exploited. Chains with Starlette Host Header bypass (CVE-2026-48710) → unauthenticated RCE (CVSS 10). 🔗 https://t.co/ftjEZPejPl #CyberSecurity #ThreatIntel #CVE202642271 #LiteLLM #AI #RCE #C
@ThreatAft
9 Jun 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA has added CVE-2026-42271 to its KEV catalog after active exploitation. The LiteLLM command injection flaw can chain with a Starlette auth bypass to enable unauthenticated RCE. #LiteLLM #CVE-2026-42271 #CVE-2026-48710 https://t.co/85aTljWenn
@TweetThreatNews
9 Jun 2026
138 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
The first confirmed autonomous LLM-agent cyberattack: an AI exploited CVE-2026-48710 ("BadHost") to exfiltrate an AWS database in under 1 hour — without human step-by-step direction. The vulnerability affected the Starlette framework, impacting FastAPI apps, vLLM, LiteLLM, MCP
@kevteachesai
8 Jun 2026
90 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ AIエージェント・MCPサーバーに認証バイパス脆弱性「BadHost」(CVE-2026-48710)。vLLM/FastAPI/LiteLLM対象。LLMが1時間以内にAWSデータを自律流出した実証あり。Starlette 1.0.1へ即時更新を https://t.co/QWEg4cL64g #AIセキュリ
@neural_nw_ai
6 Jun 2026
40 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-48710: A Maintainer's Perspective https://t.co/Dlm5hDiSmd
@PythonHub
6 Jun 2026
675 Impressions
0 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
BadHost CVE bypasses Starlette auth via Host headers. Compromises AI agents, LLM gateways, MCP servers. Patch CVE-2026-48710 now. https://t.co/RfInrCeVdj
@foursignalsdev
2 Jun 2026
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
おはモー🐮 【期限当日】LiteSpeed cPanel CVE-2026-48172、CISA KEV対処期限が今日5/29モー🐮 しかも StarletteのBadHost(CVE-2026-48710)も新たに来たモー… 今日の朝5分で: ✅ cPanelパッチ適用状況の最終確認 ✅ FastAPI/vLLM
@accell_mo_kun
28 May 2026
77 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
@ohdonpier flagged BadHost (CVE-2026-48710) in Starlette today. The point matters: MCP servers are credential aggregators by design. Vault keeps the keys outside the MCP server process, brokered per-call. One framework CVE doesn't drain everything. https://t.co/bnPfzDU0FY
@1clawAI
28 May 2026
180 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass https://t.co/H5Tg5PRSrh FastAPI vuln
@jreuben1
28 May 2026
76 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#BadHost (CVE CVE-2026-48710) was also discovered in parallel by @_nlovin and Larry Yuan (https://t.co/HHeLTaXEw2), kudos!
@marver
27 May 2026
686 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:*",
"matchCriteriaId": "4C7C6045-86A6-4FAC-AE15-B12438E9D1B4",
"versionEndExcluding": "1.0.1",
"versionStartIncluding": "0.8.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:ai_inference_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3BB03728-80D6-488F-A961-883B77B055EA",
"versionEndIncluding": "3.3.5",
"versionStartIncluding": "3.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:ansible_automation_platform:2.6:-:*:*:*:*:*:*",
"matchCriteriaId": "49F4FF35-8D34-4A57-AA85-0953FF95A2DA",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:ansible_automation_platform:2.7:-:*:*:*:*:*:*",
"matchCriteriaId": "DC59D996-1B24-462E-AB21-FFD53F909B40",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:migration_toolkit_for_applications:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4EE14B60-A259-41E7-A799-BB01D1DDF4A5",
"versionEndExcluding": "8.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:*",
"matchCriteriaId": "84CC25BD-1C5F-4BBE-AE16-C424788B82E3",
"versionEndExcluding": "3.3.5",
"versionStartIncluding": "3.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F1672580-DC29-4486-AB27-B86A37BE7BD1",
"versionEndExcluding": "3.4.2",
"versionStartIncluding": "3.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:openshift_lightspeed:-:*:*:*:*:*:*:*",
"matchCriteriaId": "C34B05C8-C19C-497F-8E1D-8F6039CDB185",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:satellite:6.17:*:*:*:*:*:*:*",
"matchCriteriaId": "342183ED-1495-4481-9164-B3ED8424B618",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:satellite:6.18:*:*:*:*:*:*:*",
"matchCriteriaId": "C2205338-7476-46DC-ABB2-52F0BBAAD01D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:redhat:satellite:6.19:*:*:*:*:*:*:*",
"matchCriteriaId": "BCFB23DD-F6A0-4CDB-98E8-E072C104ED4B",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux_ai:3.0:*:*:*:*:*:*:*",
"matchCriteriaId": "531FF57A-65AE-482C-9A43-D1F2ECAD6ED0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]