Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2026-48710: Kludex Starlette

Kludex Starlette 包含一個 HTTP 請求/ 響應走私弱點,它可以讓攻擊者向主機部分注入路徑,在認證依賴於重建的 URL 路徑時,預先確定導致認證繞行等問題的實際路徑 。這種脆弱性可以用CVE-2026-42271彌補。

CISA (English)

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

廠商
Kludex
產品
Starlette
漏洞
Kludex Starlette HTTP Request/Response Smuggling Vulnerability
加入日期
2026年9月2日
CISA 修補期限(美國聯邦機關)
2026年9月16日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-444

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02