chiprook
← Security
SecurityOctober 4, 2026, 14:00

CISA: Request Smuggling in Starlette and LiteLLM Exploited

CISA added CVE-2026-48710 in Starlette (HTTP request smuggling leading to authentication bypass) and CVE-2026-59822 in LiteLLM (improper authentication) to its Known Exploited Vulnerabilities catalog on 2 September 2026, with a federal remediation deadline of 16 September. LiteLLM versions below 1.84.0 are affected.

CISA: Request Smuggling in Starlette and LiteLLM Exploited
#Starlette#LiteLLM#CISA
Read next
Security

LiteLLM auth bypass: a one-character token unlocked MCP tools

Security

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization

Security

Critical request smuggling flaw found in Citrix NetScaler

Security

CVE-2026-42271 in LiteLLM: RCE via MCP test endpoints