CVE-2026-48710: Kludex Starlette
Kludex Starlette에는 HTTP 요청/response smuggling vulnerability가 포함되어있어 공격자가 호스트 부분으로 경로를 주사 할 수 있으므로 인증 우회와 같은 문제로 이어지는 실제 경로가 재구성 된 URL의 경로에 따라 달라집니다. 이 취약점은 CVE-2026-42271로 차질될 수 있었습니다.
CISA (English)
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
- 공급업체
- Kludex
- 제품
- Starlette
- 취약점
- Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- 추가일
- 2026. 9. 2.
- CISA 조치 기한(미국 연방기관)
- 2026. 9. 16.
- 랜섬웨어 공격 악용
- 알 수 없음
- 약점(CWE)
- CWE-444
참고 자료
이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.
최종 업데이트: · 카탈로그 버전 2026.10.02