{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-48710",
  "revision": 1,
  "title": "Starlette — Host Header Path Confusion Bypasses Access Checks",
  "summary": "Starlette before 1.0.1 did not validate the Host request header, so a crafted header can make the rebuilt request path differ from the path actually routed. Middleware or endpoints that enforce access rules on that rebuilt path, including authentication, can be bypassed.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 6.5,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
    "version": "3.1"
  },
  "epss": 0.36257,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2026-09-02",
    "prerequisites": "Network access to a Starlette app whose access checks use request.url.path rather than the raw scope path; no credentials needed"
  },
  "remediation": {
    "patch_available": true,
    "workaround_available": true,
    "fixed_in": [
      "starlette >= 1.0.1"
    ]
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade Starlette to 1.0.1 or later now; until then base path-based access checks on the raw scope path rather than request.url, and review exposed apps for abuse.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-48710",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-48710",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-48710",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "title",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-48710",
      "retrieved_at": "2026-09-20T11:09:51.520Z",
      "confidence": "high",
      "extractor": "human"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48710",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://badhost.org"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr"
    }
  ],
  "published_at": "2026-05-26T22:16:44.020Z",
  "issued_at": "2026-09-20T10:52:56.734Z",
  "tags": [
    "starlette",
    "python",
    "asgi",
    "host-header",
    "auth-bypass"
  ]
}
