First published · Last updated
CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability
Kludex Starlette has an HTTP request/response smuggling flaw that can allow attackers to inject paths into the host portion and thereby prepend the actual path. The excerpt warns this can lead to authentication bypass in cases where authentication depends on the reconstructed URL path and advises applying vendor mitigations and CISA BOD 26-04 guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 7/10
- Geographic reach
- 1/10
- Global importance
- 3/10
- Impact magnitude
- 6/10
- Positivity
- 2/10
- Urgency
- 6/10
Why it matters
Because it can enable attackers to bypass authentication in affected deployments.

