Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6302-1 | starlette security update |
Github GHSA |
GHSA-86qp-5c8j-p5mr | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks |
Fri, 04 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 03 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat ai Inference Server Redhat ansible Automation Platform Redhat enterprise Linux Ai Redhat migration Toolkit For Applications Redhat openshift Ai Redhat openshift Lightspeed Redhat satellite |
|
| CPEs | cpe:2.3:a:redhat:ai_inference_server:*:*:*:*:*:*:*:* cpe:2.3:a:redhat:ansible_automation_platform:2.6:-:*:*:*:*:*:* cpe:2.3:a:redhat:ansible_automation_platform:2.7:-:*:*:*:*:*:* cpe:2.3:a:redhat:migration_toolkit_for_applications:*:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_ai:*:*:*:*:*:*:*:* cpe:2.3:a:redhat:openshift_lightspeed:-:*:*:*:*:*:*:* cpe:2.3:a:redhat:satellite:6.17:*:*:*:*:*:*:* cpe:2.3:a:redhat:satellite:6.18:*:*:*:*:*:*:* cpe:2.3:a:redhat:satellite:6.19:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux_ai:3.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Redhat
Redhat ai Inference Server Redhat ansible Automation Platform Redhat enterprise Linux Ai Redhat migration Toolkit For Applications Redhat openshift Ai Redhat openshift Lightspeed Redhat satellite |
Thu, 03 Sep 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Wed, 02 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 02 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Fri, 28 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Encode
Encode starlette |
|
| CPEs | cpe:2.3:a:encode:starlette:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Encode
Encode starlette |
Thu, 28 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1289 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 27 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kludex
Kludex starlette |
|
| Vendors & Products |
Kludex
Kludex starlette |
Tue, 26 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values. | |
| Title | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks | |
| Weaknesses | CWE-444 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-04T12:05:00.370Z
Reserved: 2026-05-22T18:47:27.755Z
Link: CVE-2026-48710
Updated: 2026-09-03T12:04:32.478Z
Status : Analyzed
Published: 2026-05-26T22:16:44.020
Modified: 2026-09-04T15:59:29.557
Link: CVE-2026-48710
OpenCVE Enrichment
Updated: 2026-09-04T15:00:05Z
Debian DSA
Github GHSA