Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "smuggling", "starlette"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Government"] ยท au_impact: true

CVE-2026-48710

Affected product: Kludex Starlette (HTTP request/response smuggling)

Patched version: Refer to vendor advisory

Active exploitation: Yes โ€” added to CISA Known Exploited Vulnerabilities catalog on 2026-09-02

Assessment

CISA added this Starlette HTTP request/response smuggling flaw to its Known Exploited Vulnerabilities catalog on 2 September, confirming in-the-wild exploitation. Starlette underpins widely deployed Python web frameworks, so the smuggling flaw can enable request-cache poisoning and request routing attacks in applications built on it. Patching per vendor guidance is required, with federal agencies bound by binding operational directives.