Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:22992 cve-icon
https://access.redhat.com/errata/RHSA-2026:22993 cve-icon
https://access.redhat.com/errata/RHSA-2026:23346 cve-icon
https://access.redhat.com/errata/RHSA-2026:24866 cve-icon
https://access.redhat.com/errata/RHSA-2026:26226 cve-icon
https://access.redhat.com/errata/RHSA-2026:30088 cve-icon
https://access.redhat.com/errata/RHSA-2026:30089 cve-icon
https://access.redhat.com/errata/RHSA-2026:34456 cve-icon
https://access.redhat.com/errata/RHSA-2026:34526 cve-icon
https://access.redhat.com/errata/RHSA-2026:34532 cve-icon
https://access.redhat.com/errata/RHSA-2026:37275 cve-icon
https://access.redhat.com/errata/RHSA-2026:43038 cve-icon
https://access.redhat.com/errata/RHSA-2026:44696 cve-icon
https://access.redhat.com/errata/RHSA-2026:51357 cve-icon
https://access.redhat.com/errata/RHSA-2026:60520 cve-icon
https://access.redhat.com/security/cve/CVE-2026-48710 cve-icon
https://badhost.org cve-icon cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2481742 cve-icon
https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6 cve-icon cve-icon cve-icon
https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr cve-icon cve-icon cve-icon
https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yaml cve-icon cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-48710 cve-icon
https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette cve-icon cve-icon cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.json cve-icon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48710 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-48710 cve-icon
https://www.secwest.net/starlette cve-icon cve-icon cve-icon
https://www.wiz.io/blog/ai-infrastructure-honeypot cve-icon cve-icon
https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette cve-icon cve-icon cve-icon
https:/www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points cve-icon cve-icon
History

Thu, 03 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat enterprise Linux Ai
Redhat migration Toolkit For Applications
Redhat openshift Ai
Redhat openshift Lightspeed
Redhat satellite
CPEs cpe:2.3:a:redhat:ai_inference_server:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.6:-:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_automation_platform:2.7:-:*:*:*:*:*:*
cpe:2.3:a:redhat:migration_toolkit_for_applications:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_lightspeed:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:6.17:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:6.18:*:*:*:*:*:*:*
cpe:2.3:a:redhat:satellite:6.19:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_ai:3.0:*:*:*:*:*:*:*
Vendors & Products Redhat
Redhat ai Inference Server
Redhat ansible Automation Platform
Redhat enterprise Linux Ai
Redhat migration Toolkit For Applications
Redhat openshift Ai
Redhat openshift Lightspeed
Redhat satellite

Thu, 03 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 18:30:00 +0000


Wed, 02 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-09-02T00:00:00+00:00', 'dueDate': '2026-09-16T00:00:00+00:00'}


Fri, 28 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
References

Tue, 16 Jun 2026 13:30:00 +0000


Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Encode
Encode starlette
CPEs cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:*
Vendors & Products Encode
Encode starlette

Thu, 28 May 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1289
References
Metrics threat_severity

None

threat_severity

Important


Wed, 27 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Kludex
Kludex starlette
Vendors & Products Kludex
Kludex starlette

Tue, 26 May 2026 22:15:00 +0000

Type Values Removed Values Added
Description Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.
Title Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks
Weaknesses CWE-444
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-05-26T21:54:54.393Z

Updated: 2026-09-04T12:05:00.370Z

Reserved: 2026-05-22T18:47:27.755Z

Link: CVE-2026-48710

cve-icon Vulnrichment

Updated: 2026-09-03T12:04:32.478Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-26T22:16:44.020

Modified: 2026-09-03T15:39:44.470

Link: CVE-2026-48710

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-26T21:54:54Z

Links: CVE-2026-48710 - Bugzilla