Skip to main content
QUIETLYTIC
Vulnerability

Starlette Vulnerability (CVE-2026-48710)

CVE-2026-48710 is a CVSS 6.5 Host-header request smuggling flaw in the Starlette ASGI framework, confirmed exploited per CISA KEV.

CVE-2026-48710
Threat Level
MEDIUM
CVSS
6.5
Status
Active Exploitation
Confidence
High
Affected Products
Starlette (before 1.0.1)

CVE-2026-48710 carries a CVSS 3.1 base score of 6.5 against Starlette, the lightweight ASGI framework and toolkit that underpins FastAPI and a wide range of other Python web services. NVD and CISA’s own KEV entry both classify it under CWE-444 (Inconsistent Interpretation of HTTP Requests, the request-smuggling weakness family) and CWE-1289 (Improper Validation of Unsafe Equivalence). CISA added this CVE to its Known Exploited Vulnerabilities catalog on September 2, 2026, confirming real-world exploitation directly rather than through a single vendor report; VulnCheck’s KEV feed independently corroborates the same exploitation status and date.

Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.

What the flaw is

Per NVD, versions of Starlette before 1.0.1 did not validate the HTTP Host request header before using it to reconstruct request.url. Starlette’s routing algorithm makes its decisions against the raw HTTP path, but request.url — the value application code and middleware typically inspect — is separately rebuilt from the Host header. A malformed or attacker-crafted Host header could make request.url.path diverge from the path Starlette actually routed the request to. Any middleware or endpoint logic that enforces security restrictions by checking request.url rather than the raw ASGI scope path could be bypassed as a result — the request that gets inspected and the request that gets served are not necessarily the same one.

The fix, in 1.0.1 and later, validates the Host header against the grammar defined in RFC 9112 §3.2 and RFC 3986 §3.2.2 before using it, and falls back to the ASGI scope["server"] value when the header is malformed.

Evidence and confidence

  • High confidence — exploitation status, corroborated independently by CISA KEV and VulnCheck KEV, both dated September 2, 2026.
  • High confidence — the CWE-444/CWE-1289 classification, corroborated across NVD and CISA KEV.
  • Medium confidence — the CVSS 6.5 score and vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), which trace to NVD alone in our current ingestion.
  • Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.36257, a 98.4th percentile score as of our ingestion, an unusually high figure that lines up with the confirmed CISA listing.

No field is in conflict between our sources. NVD’s own reference list for this CVE is unusually extensive, including a public disclosure writeup, a GitHub Security Advisory, an independent security-firm advisory, and more than a dozen downstream Red Hat errata entries — reflecting how widely Starlette is vendored as a transitive dependency.

Why this matters

A request-smuggling-class bug in a framework this widely embedded is not really a single vulnerability — it is a class of bugs waiting to be found in every application built on top of it. Any Starlette-based service (including FastAPI applications, which sit directly on Starlette’s routing layer) that relies on request.url for host-based access control, virtual-hosting decisions, or security middleware should treat a pinned pre-1.0.1 Starlette version as carrying that risk regardless of the application’s own code. CISA’s confirmed exploitation, corroborated independently by VulnCheck, means this is being actively targeted rather than a theoretical parsing edge case.

Frequently Asked Questions

What is CVE-2026-48710? A CVSS 6.5 HTTP request/response smuggling vulnerability (CWE-444, CWE-1289) in the Starlette ASGI framework before version 1.0.1, caused by unvalidated Host header data being used to reconstruct request.url.

Is CVE-2026-48710 being actively exploited? Yes, per two independent sources: CISA’s Known Exploited Vulnerabilities catalog and VulnCheck’s KEV feed, both dated September 2, 2026.

Does this affect FastAPI too? FastAPI is built directly on Starlette’s routing and request layer, so applications running FastAPI on a pre-1.0.1 Starlette version inherit the same exposure. Check your dependency-pinned Starlette version, not just your FastAPI version.

Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.

Which version fixes this? Starlette 1.0.1 and later. The fix validates the Host header against RFC 9112/RFC 3986 grammar before use.


Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-48710. Exploitation status and the September 2, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry, independently corroborated by VulnCheck KEV. Fix commit and advisory: GitHub Security Advisory GHSA-86qp-5c8j-p5mr. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 CISA Known Exploited Vulnerabilities (KEV) Catalog
03 VulnCheck KEV

Related intelligence


Analyst tools