## Overview
A weaponized exploit for CVE-2026-48710 has emerged, targeting the Kludex Starlette framework. This vulnerability allows attackers to manipulate the HTTP `Host` request header, leading to potential bypasses of security restrictions.
## Technical Details
Prior to version 1.0.1, the Starlette framework did not validate the `Host` header before reconstructing `request.url`. The routing algorithm depends on the raw HTTP path, while `request.url` is built from the `Host` header. If an attacker sends a malformed `Host` header, the reconstructed `request.url.path` may differ from the actual path requested. This discrepancy can allow malicious actors to bypass middleware and endpoint security measures that rely on `request.url` instead of the raw `scope` path.
## Impact
The vulnerability has a CVSS score of 6.5, indicating a moderate risk. Systems using vulnerable versions of Starlette may face unauthorized access or manipulation of request handling processes. Attackers can exploit this flaw to bypass security controls, potentially leading to further exploitation of the application.
## Mitigation
Defenders must upgrade to Kludex Starlette version 1.0.1 or later to mitigate this vulnerability. The updated version includes validation of the `Host` header against RFC 9112 §3.2 and RFC 3986 §3.2.2. This validation ensures that malformed headers are handled correctly, falling back to `scope["server"]` for any invalid values. Immediate action is recommended to secure affected systems.
CSURFACE Threat Sensor