CVE-2026-48710

MEDIUMCVSS 6.5/10Actively ExploitedEPSS 36.26%

Last modified

CVE-2026-48710 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. CISA has confirmed active exploitation in the wild. EPSS estimates a 36.26% chance of exploitation in the next 30 days.

Description

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.

Metrics

EPSS Probability
36.26%

98.4th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
EncodeStarlette>= 0.8.3, < 1.0.1
RedhatAi Inference Server>= 3.3.0, <= 3.3.5
RedhatAnsible Automation Platform2.6
RedhatAnsible Automation Platform2.7
RedhatMigration Toolkit For Applications< 8.2.0
RedhatOpenshift Ai>= 3.3, < 3.3.5
RedhatOpenshift Ai>= 3.4, < 3.4.2
RedhatOpenshift LightspeedAll versions
RedhatSatellite6.17
RedhatSatellite6.18
RedhatSatellite6.19
RedhatEnterprise Linux Ai3.0

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-48710?
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.
How severe is CVE-2026-48710?
CVE-2026-48710 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 36.26% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2026-48710?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-48710?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST