| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6302-1 | starlette security update |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 28 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1289 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 27 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kludex
Kludex starlette |
|
| Vendors & Products |
Kludex
Kludex starlette |
Tue, 26 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values. | |
| Title | Starlette has missing Host header validation that poisons request.url.path, bypassing path-based security checks | |
| Weaknesses | CWE-444 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-27T14:26:57.893Z
Reserved: 2026-05-22T18:47:27.755Z
Link: CVE-2026-48710
Updated: 2026-05-27T14:26:50.071Z
Status : Awaiting Analysis
Published: 2026-05-26T22:16:44.020
Modified: 2026-05-29T16:19:35.753
Link: CVE-2026-48710
OpenCVE Enrichment
Updated: 2026-05-28T04:45:07Z
Debian DSA