CVE-2026-48710: Kludex Starlette
Kludex Starlette bevat een HTTP verzoek/antwoord smokkel kwetsbaarheid die aanvallers in staat zou kunnen stellen om paden in het host-gedeelte te injecteren, voorafgaand aan de werkelijke pad leidend tot problemen zoals authenticatie bypass wanneer de authenticatie afhankelijk is van de gereconstrueerde URL. Deze kwetsbaarheid kan worden gechanteerd met CVE-2026-42271.
CISA (English)
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
- Leverancier
- Kludex
- Product
- Starlette
- Kwetsbaarheid
- Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- Toegevoegd op
- 2 sep 2026
- CISA-termijn (Amerikaanse federale instanties)
- 16 sep 2026
- Bekend gebruik in ransomwarecampagnes
- Onbekend
- Zwakte (CWE)
- CWE-444
Referenties
Laatst bijgewerkt: · Catalogusversie 2026.10.02