CVE-2026-48710
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: starlette is a lightweight ASGI framework/toolkit.
CISA federal remediation date Sep 16
Vulnerabilities & Exploits · Web App Attack
A direct Starlette or FastAPI deployment can trust the wrong request and still serve a protected route. The bug lets middleware see one URL while the router uses another, so app-level host or path checks can be bypassed without credentials. This breaks the assumption that framework checks are enough when no compliant reverse proxy normalizes the request first.
CVE-2026-48710 sits in Starlette’s handling of malformed Host headers, where a small change can shift where the path begins. Starlette 1.0.1 is the fixed release. The issue matters across FastAPI-based apps and model-facing services such as LLM gateways, MCP servers, LiteLLM, and vLLM, because the exposed control is the app’s own access check rather than the network edge.
The risk is limited to setups that make trust decisions from the raw request before normalization, but that is exactly how many internal tools and API gateways are built.
1 source · May 27
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: starlette is a lightweight ASGI framework/toolkit.
CISA federal remediation date Sep 16
CSO Online
FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework
Researchers who found the bug warn that its Moderate rating understates a threat reaching across LLM gateways, MCP servers and agent infrastructure.
originalPart of the PlainSec briefing for 2026-05-28
Every edition of this story: Starlette Host Parsing Lets Direct Apps Misread Requests