CVE-2026-48710: Kludex Starlette
Kludex Starlette 包含一個 HTTP 請求/ 響應走私弱點,它可以讓攻擊者向主機部分注入路徑,在認證依賴於重建的 URL 路徑時,預先確定導致認證繞行等問題的實際路徑 。這種脆弱性可以用CVE-2026-42271彌補。
CISA (English)
Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.
- 廠商
- Kludex
- 產品
- Starlette
- 漏洞
- Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- 加入日期
- 2026年9月2日
- CISA 修補期限(美國聯邦機關)
- 2026年9月16日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-444
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02