ALPHACON BBSGość · pl
← Podatności

Podatności / CISA KEV · AKTYWNIE WYKORZYSTYWANE · CVSS 6.5

CVE-2026-48710 · Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Identyfikator
CVE-2026-48710
CVSS
6.5 MEDIUM
CISA KEV
AKTYWNIE WYKORZYSTYWANE
Producent
Kludex
Produkt
Starlette
Dodano do KEV
2026-09-02
Termin CISA
2026-09-16
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.