Planet Briefing

First published · Last updated

CVE-2026-48710: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex Starlette has an HTTP request/response smuggling flaw that can allow attackers to inject paths into the host portion and thereby prepend the actual path. The excerpt warns this can lead to authentication bypass in cases where authentication depends on the reconstructed URL path and advises applying vendor mitigations and CISA BOD 26-04 guidance.

Categories: technology

Generated scores

Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.

Confidence
7/10
Geographic reach
1/10
Global importance
3/10
Impact magnitude
6/10
Positivity
2/10
Urgency
6/10

Why it matters

Because it can enable attackers to bypass authentication in affected deployments.

Location

Sources

Report an issue