## Overview
CISA added CVE-2026-48710 to its Known Exploited Vulnerabilities (KEV) catalog on September 2, 2026. This vulnerability affects the Starlette framework, a lightweight ASGI toolkit. It allows attackers to exploit the HTTP `Host` request header, which is not validated before reconstructing `request.url`. The addition to the KEV list signals a federal deadline for remediation due to evidence of exploitation.
## Technical Details
The flaw exists in versions of Starlette prior to 1.0.1. When the `Host` header is malformed, it can lead to discrepancies between `request.url.path` and the actual requested path. This occurs because the routing algorithm relies on the raw HTTP path while `request.url` is built from the `Host` header. As a result, security measures that depend on `request.url` can be bypassed, potentially allowing unauthorized access.
## Impact
Attackers can inject paths into the host part of requests, leading to vulnerabilities such as authentication bypass. This is particularly concerning for applications that enforce security restrictions based on the reconstructed URL’s path. The vulnerability can be chained with CVE-2026-42271, increasing its severity.
## Mitigation
Defenders should upgrade to Starlette version 1.0.1 or later. The updated version validates the `Host` header against RFC 9112 §3.2 and RFC 3986 §3.2.2. It also defaults to `scope["server"]` for malformed values, which helps prevent exploitation. Immediate action is recommended to secure applications using this framework.
CSURFACE Threat Sensor