Starlette CVE-2026-48710 enters KEV: malformed Host values can bypass path-based controls

Published 10 Sep 2026 · Severity: medium

CISA added Starlette CVE-2026-48710 to KEV on 2 September 2026. In affected versions, a malformed Host header can make request.url.path differ from the route actually executed, potentially bypassing middleware or endpoints that use the reconstructed URL for security decisions. Upgrade to Starlette 1.0.1 and review applications that implement path-based authorisation.