type: vulnerability ยท created: 2026-09-03 ยท updated: 2026-09-03 ยท tags: ["cve", "vulnerability", "smuggling", "starlette"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Government"] ยท au_impact: true
CVE-2026-48710
Affected product: Kludex Starlette (HTTP request/response smuggling)
Patched version: Refer to vendor advisory
Active exploitation: Yes โ added to CISA Known Exploited Vulnerabilities catalog on 2026-09-02
Assessment
CISA added this Starlette HTTP request/response smuggling flaw to its Known Exploited Vulnerabilities catalog on 2 September, confirming in-the-wild exploitation. Starlette underpins widely deployed Python web frameworks, so the smuggling flaw can enable request-cache poisoning and request routing attacks in applications built on it. Patching per vendor guidance is required, with federal agencies bound by binding operational directives.