CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization
A vulnerability CVE-2026-48710 (BadHost) was found in the ASGI framework Starlette (versions 0.8.3–1.0.0): a malformed Host header distorts request.url.path and bypasses path-prefix authorization checks. CISA added it to the exploited vulnerabilities catalog; the fix is Starlette 1.0.1.
- CVSS 6.5 per maintainers, X41 D-Sec rates risk at 7.0
- Starlette 0.8.3–1.0.0 affected, fixed in version 1.0.1
- Chained with LiteLLM gives unauthenticated RCE, CVSS 10.0
- CISA added the CVE to the exploited vulnerabilities catalog
Read next
Security