# CVE-2026-48710: Starlette - Improper Access Control

> Live exploitation tracking for CVE-2026-48710 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-48710

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 6.5
- **Public exploit available:** Yes
- **Affected products:** Kludex Starlette
- **Weaknesses:** CWE-444 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')); CWE-1289 (Improper Validation of Unsafe Equivalence in Input)
- **Tags:** python, web_application

## Description

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.

## CrowdSec analysis

[CVE-2026-48710](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-48710) is an improper access control vulnerability in the Starlette ASGI framework, where the HTTP Host header was not properly validated before being used to reconstruct request URLs. This flaw could allow attackers to craft malicious Host headers, potentially bypassing security restrictions enforced by middleware or endpoints that rely on request.url for access control. As a result, unauthorized access to protected resources or endpoints may be possible until the issue is patched.

CrowdSec has been tracking this vulnerability and its exploits since 1st of July 2026.

According to CrowdSec data, while opportunistic exploitation dominates, a portion of threat actors trying to exploit CVE-2026-48710 apply basic targeting methods such as port or service detection. This indicates emerging patterns of selective targeting.
Data from the CrowdSec community also indicates a gradual decrease in attacks targeting CVE-2026-48710. While still present in the wild, exploitation levels have dropped noticeably week-over-week. This may signal that the vulnerability is becoming less relevant or that defenses are improving fast enough for attackers to lose interest.

Attackers exploit this vulnerability by sending HTTP requests with a specially crafted Host header (such as `Host: a/?x=`) to endpoints like `/mcp-rest/test/connection`, bypassing middleware or path-based security checks that rely on improper URL reconstruction.

## Timeline

- 2026-05-26: CVE Published. CVE-2026-48710 is published to NVD.
- 2026-07-01: Rule Released. CrowdSec releases a rule to detect CVE-2026-48710 exploitation attempts against the CrowdSec Network.
- 2026-07-02: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-48710 for the first time.
- 2026-09-02: CISA KEV. CVE-2026-48710 is added to the Known Exploited Vulnerabilities catalog by CISA.
- 2026-09-16: CISA Remediation Deadline. Expiration of the CISA remediation deadline as described in [BOD 22-01](https://www.cisa.gov/news-events/directives/bod-22-01-reducing-significant-risk-known-exploited-vulnerabilities).

## References

- https://www.secwest.net/starlette
- https://www.x41-dsec.de/lab/advisories/x41-2026-002-starlette
- https://access.redhat.com/errata/RHSA-2026:30089
- https://access.redhat.com/security/cve/CVE-2026-48710
- https://access.redhat.com/errata/RHSA-2026:22993
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48710.json
- https://github.com/pypa/advisory-database/tree/main/vulns/starlette/PYSEC-2026-161.yaml
- https://access.redhat.com/errata/RHSA-2026:24866
- https://github.com/Kludex/starlette/commit/764dab0dcfb9033d75442d7a359645c9f94648c6
- https://access.redhat.com/errata/RHSA-2026:30088
- https://ostif.org/disclosing-the-badhost-vulnerability-in-starlette
- https://bugzilla.redhat.com/show_bug.cgi?id=2481742
- https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr
- https://access.redhat.com/errata/RHSA-2026:23346
- https://access.redhat.com/errata/RHSA-2026:22992
- https://access.redhat.com/errata/RHSA-2026:26226
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-48710.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-48710) follows observed exploitation activity for CVE-2026-48710. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
