CVE-2026-48710
Kludex starlette, Red Hat AI Inference Server 3.3, Red Hat Ansible Automation Platform 2.6
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1...
- CVSS
- 6.5
- EPSS
- - - percentile
- CISA KEV
- Listed
- Published
- 2026.05.27