CISA: Request Smuggling in Starlette and LiteLLM Exploited
CISA added CVE-2026-48710 in Starlette (HTTP request smuggling leading to authentication bypass) and CVE-2026-59822 in LiteLLM (improper authentication) to its Known Exploited Vulnerabilities catalog on 2 September 2026, with a federal remediation deadline of 16 September. LiteLLM versions below 1.84.0 are affected.
- CVE-2026-48710 in Starlette: request smuggling leads to authentication bypass
- CVE-2026-59822 in LiteLLM: improper authentication, versions below 1.84.0 affected
- CISA added both to KEV on 2 September, remediation deadline 16 September
- Advisory recommends checking ~/.ssh/authorized_keys for host persistence
Read next
Security