← All Advisories

Kludex Starlette's HTTP Request Smuggling Vulnerability Allows Network-Adjacent Attackers to Bypass Security Controls and Poison Shared HTTP Connections

Last refreshed2026-09-27

Status: KEV  |  Advisory ID: CVE-2026-48710

Key Details

CVECVE-2026-48710
Vulnerability NameKludex Starlette HTTP Request/Response Smuggling Vulnerability
CVSS Score / Version6.5 (Medium) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is low; availability impact is none.
Affected productssee table below
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-09-02.
Exploitation prediction (EPSS)7.06% probability of exploitation in the next 30 days (94% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
KludexStarlette
encodeStarlette
Red HatAI Inference Server
Red HatAnsible Automation Platform
Red HatMigration Toolkit for Applications
Red HatOpenShift AI
Red HatOpenShift Lightspeed
Red HatSatellite
Red HatEnterprise Linux AI
SubsystemsCore Infrastructure, EWS Workstation Delivery/Virtualization
SectorsAll Sectors

What to Know

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.

What to Do

Monitor Kludex, encode, and Red Hat's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-48710
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-48710
Vendor advisoryhttps://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr

KEV Required Action

FieldValue
KEV Linkhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
Date Added to KEV2026-09-02