CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-48710Public Exploit

Starlette - Improper Access Control (CVE-2026-48710)

PublishedMay 26, 2026
First SeenJul 2, 2026
Last Seen
Reported
CVSS6.5
pythonweb_application

Description

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP Host request header was not validated before being used to reconstruct request.url. Because the routing algorithm relies on the raw HTTP path while request.url is rebuilt from the Host header, a malformed header could make request.url.path differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on request.url (rather than the raw scope path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the Host header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing request.url and falls back to scope["server"] for malformed values.

psychologyCrowdSec Analysis

CVE-2026-48710 is an improper access control vulnerability in the Starlette ASGI framework, where the HTTP Host header was not properly validated before being used to reconstruct request URLs. This flaw could allow attackers to craft malicious Host headers, potentially bypassing security restrictions enforced by middleware or endpoints that rely on request.url for access control. As a result, unauthorized access to protected resources or endpoints may be possible until the issue is patched.

CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-48710 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting. Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-48710. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit this vulnerability by sending HTTP requests with a specially crafted Host header (such as Host: a/?x=) to endpoints like /mcp-rest/test/connection, bypassing middleware or path-based security checks that rely on improper URL reconstruction.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-05-26
Rule Released2026-07-01
CrowdSec First Seen2026-07-02
CISA KEV2026-09-02
CISA Remediation Deadline2026-09-16

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.