Security
Loading…

CVE-2026-48710

MEDIUMCVSS 6.5Known Exploited
Description

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Timeline
Published:May 26th, 2026 10:16 PM
Last modified:September 4th, 2026 3:59 PM
Added to KEV:September 2nd, 2026
CVSS Scoring

CVSS v3: 6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected Software
From NVD CPE configuration data

Vendors

encoderedhat

Products

starletteai_inference_serveransible_automation_platformmigration_toolkit_for_applicationsopenshift_aiopenshift_lightspeedsatelliteenterprise_linux_ai
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

Source: NIST NVD · Data may lag official sources by up to one minute